Settings

Theme

New Chrome Zero-Day

kaspersky.com

26 points by bsaunder 6 years ago · 11 comments

Reader

maxmcd 6 years ago

Previous discussion: https://news.ycombinator.com/item?id=21425804

NikolaeVarius 6 years ago

Was already patched on Oct 31 https://chromereleases.googleblog.com/2019/10/stable-channel...

maerF0x0 6 years ago

I would suggest we put the date in these kind of 0 day titles. Nov 4 in this case...

andrewstuart 6 years ago

Why would cybercriminals not just report the bug and pick up the cash from Google? Is it genuinely that much more lucrative to exploit it?

  • imposterr 6 years ago

    You can only sell to Google once. You can sell it to different exploit houses many times.

    But also historically, some places pay in the several hundred thousand compared to tech companies that pay in the tens of thousands. So even if they only sell it once, they can make more.

  • lawnchair_larry 6 years ago

    It isn’t cybercriminals. Cybercriminals pretty much never have top tier 0day. This one is North Korean intelligence, and they get far more value out of it than Google is willing to pay.

  • wnevets 6 years ago

    >Why would cybercriminals not just report the bug and pick up the cash from Google?

    Probably because they're not the ones actually finding the bugs.

thephyber 6 years ago

The CVE is still embargoed[1] as of the time of this comment. =/

[1] https://nvd.nist.gov/vuln/detail/CVE-2019-13720

0xdeadb00f 6 years ago

I'm assuming this doesn't affect Chromium, or Chromium(-based) browsers on Android then? Seeing as it isn't mentioned.

  • mark-r 6 years ago

    The article specifically mentions that it was discovered on Windows, but that doesn't mean some variation couldn't exist for other platforms.

    • 0xdeadb00f 6 years ago

      I meant more along the lines of: is this a Chrome specific vulnerability or is the vuln apparent in Chromium and thus are all Chromium-based browsers (on any platform) affected?

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection