Google's Chrome browser is first to fall at Pwn2own hacking contest

After managing to evade hackers for a number of years, Google's browser is targeted by French group Vupen which has controversial method of funding itself: selling vulnerabilities to governments

Well, that's a turnup for the books: Google's Chrome browser has been the first to be hacked at the annual Pwn2own competition. Having seen its product being untouchable for the past two years, the company may have become a little overconfident - and offered up to $60,000 to anyone who could hack it at all, up to a limit of $1m.

It was a challenge which a French team, Vupen, was very happy to take - and break. In fact, they hacked Chrome during the first five minutes of the competition, and (under the new rules) took 32 points. It also earns them $20,000 from Chrome for using bugs in Chrome itself to gain "full unsandboxed code execution". Note: A representative for Pwn2own tells us that "Vupen did not compete in the Pwnium competition and therefore will not receive any money from Google.

Also: Google has updated Chrome to fix the hole exploited by the hack. (Thanks @rquick for the link.)

The hack was carried out on the Windows version: according to Justin Schuh, of Google's Chrome team, the exploit "didn't break out of the sandbox… it avoided the sandbox". Update: Pwn2own says that the sandbox-avoiding exploit "is true for the competitor in Pwnium. Vupen's was a full sandbox escape for Pwn2own."

The Twitter feed for the contest (which began at 12 noon Pacific time on Wednesday) indicates that Safari was the next to fall - again by Vupen.

Vupen has attracted some controversy by discovering and then selling vulnerabilities and exploits to government customers - a business that one might think is both lucrative and risky. Chaouki Bekrar, the co-founder and head of research, told ZDNet that "We had to use two vulnerabilities. The first one was to bypass DEP and ASLR on Windows and a second one to break out of the Chrome sandbox."

In fact the Vupen team had achieved this last May, though too late of course for the March-timed Pwn2own. At the time they said that

The user is tricked into visiting a specially crafted web page hosting the exploit which will execute various payloads to ultimately download the Calculator from a remote location and launch it outside the sandbox (at Medium integrity level).

No trickery is needed at the contest, of course, because the teams can direct the browsers to whatever pages they've set up to exploit vulnerabilities. Vupen said that they have come armed with vulnerabilities which will exploit each of the browsers on show - Internet Explorer, Firefox, Chrome and Safari. But they decided to go after Chrome first, Bekrar told ZDNet: "We wanted to show that Chrome was not unbreakable. Last year, we saw a lot of headlines that no one could hack Chrome. We wanted to make sure it was the first to fall this year."

Equally he was complimentary about Chrome, generally seen as possibly the most secure browser because of its hefty sandboxing. "The Chrome sandbox is the most secure sandbox out there," Bekrar told ZDNet. "It's not an easy task to create a full exploit to bypass all the protections in the sandbox. I can say that Chrome is one of the most secure browsers available."

An interesting point for Vupen is that all of the hacks used at Pwn2own are meant then to be disclosed publicly - which implies that they have either sold them already to customers (who will have been told to make use of them by this date, or may be feeling a little narked), or that they're just polishing their reputation by hacking everything in sight. With day one over, Vupen looks to be far ahead of the rest. Update: Pwn2own tells us that "Everything Vupen displays at Pwn2own was created especially for this competition. The exploits were not previously sold to customers."

There's a page with the progress of the Pwn2own competition. Vupen is miles ahead of everyone at present with 124 points. The competition ends on Friday 9 March.

The competition, which has been running for a number of years, has usually seen Apple's Safari being the first to fall (usually at the hands of fabled ex-NSA hacker Charlie Miller), with Firefox and Internet Explorer surviving longer. The advent of Chrome in the past few years has changed the landscape: its sandboxing and general security model has made it proof against repeated attacks. (The browsers run on the latest, fully-patched versions of Windows or Mac OSX; this year, it's Windows 7 and Lion.)

Contributor

Charles Arthur

The GuardianTramp

Related Content

Article image
Browser autofill used to steal personal details in new phishing attack
Chrome, Safari, Opera and extensions such as LastPass can be tricked into leaking private information using hidden text boxes, developer finds

Samuel Gibbs

10, Jan, 2017 @11:24 AM

Pwn2Own -- it's a wrap

With the Pwn2Own hacking contest over, Google's Chrome has emerged with the Gold while Apple's twice-pwned Safari holds the wooden spoon

Jack Schofield

21, Mar, 2009 @10:24 PM

Article image
How can I back up my bookmarks and access them online?
Jenifer wants a backup while EC wants a replacement for Google+, which is shutting down

Jack Schofield

07, Feb, 2019 @8:00 AM

Chrome gains again as Microsoft's browser share slips below 60%

Microsoft's Internet Explorer has been losing market share for years, but now its losses are going mainly to Google Chrome instead of Firefox. Meanwhile in operating systems, it's Windows 7 that is growing fast, and it is on track to overtake Vista, according to figures released by Net Applications

Jack Schofield

04, May, 2010 @4:02 PM

Article image
Google Chrome security flaw offers unrestricted password access

Plain text logon details for email, social networks and company systems stored in browser's Settings panel. By Charles Arthur

Charles Arthur

07, Aug, 2013 @9:57 AM

Google Chrome offers poor password security, on CIS tests

Google's Chrome gets the headline, while Apple's Safari ties for last place in the CIS password security tests -- but all the browsers look bad

Jack Schofield

14, Dec, 2008 @11:45 PM

Microsoft's browser choice – which one is best?
Internet Explorer, Firefox, Safari or Chrome – a brief guide to the best of the browsers. By Charles Arthur

Charles Arthur

01, Mar, 2010 @4:45 PM

Article image
Windows 10: Microsoft is looking to force people to use its Edge browser
Company looks for feedback on change that will make Windows Mail links open in Edge even if users have Chrome or Firefox set as default

Samuel Gibbs

19, Mar, 2018 @12:46 PM

First security hole in Chrome is one already fixed in Safari

Chrome may not have as many security holes as Safari, but it's been shipped with one that Safari has already fixed

Jack Schofield

03, Sep, 2008 @8:44 PM

Firefox boss responds to Google's Chrome

Mozilla's best friend is about to invade Mozilla's prime market with a Windows browser

Jack Schofield

02, Sep, 2008 @10:08 AM