Zero Twitter

  



A security researcher has dropped a zero-day remote code execution vulnerability on Twitter that works on the current version of Google Chrome and Microsoft Edge.

  1. Zero Smash Player Twitter
  2. Generation Zero Twitter

A zero-day vulnerability is a security bug that has been publicly disclosed but has not been patched in the released version of the affected software.

Welcome to Miami-Dade County Public Schools. Miami-Dade County Public Schools is the fourth largest school district in the United States, comprised of 392 schools, 345,000 students and over 40,000 employees. Fermilab explores the fundamental nature of matter and energy by providing leadership and resources for qualified researchers to conduct basic research at the frontiers of high energy physics. Located in Batavia, Illinois. Our agenda is simple: The ZERO TO THREE Policy Center promotes good health, strong families, and positive early learning experiences for all infants and toddlers, with special emphasis on those who are the most vulnerable and in need. 1 hour ago  Zero Point is a new comic set in the Fortnite universe, which looks at the battle royale game from Batman’s perspective. A new way of looking at the game. Twitter Facebook. 1 day ago  Sub-Zero in 'Mortal Kombat' Is the Coolest Movie Villain in Recent Memory Joe Taslim brings it as the reworked and frightening ice-conjuring Sub-Zero, who has a legendary score to settle.

Today, security researcher Rajvardhan Agarwal released a working proof-of-concept (PoC) exploit for a remote code execution vulnerability for the V8 JavaScript engine in Chromium-based browsers.

Just here to drop a chrome 0day. Yes you read that right.https://t.co/sKDKmRYWBPpic.twitter.com/PpVJrVitLR

— Rajvardhan Agarwal (@r4j0x00) April 12, 2021

While Agarwal states that the vulnerability is fixed in the latest version of the V8 JavaScript engine, it is not clear when Google will roll out the Google Chrome.

When the PoC HTML file, and its corresponding JavaScript file, are loaded in a Chromium-based browser, it will exploit the vulnerability to launch the Windows calculator (calc.exe) program.

While no developer likes a zero-day release for their software, the good thing is that Agarwal's zero-day cannot currently escape the browser's sandbox. The Chrome sandbox is a browser security boundary that prevents remote code execution vulnerabilities from launching programs on the host computer.

Twitter

For Agarwal's zero-day RCE exploit to work, it would need to be chained with another vulnerability that can allow the exploit to escape the Chromium sandbox.

To test the exploit, BleepingComputer launched the Microsoft Edge and Google Chrome browsers with the --no-sandbox flag, which turns off the Chromium sandbox.

With the sandbox disabled, we could use Agarwal's exploit to launch Calculator on our Windows 10 device. Our tests' exploitable versions are Google Chrome 89.0.4389.114 and Microsoft Edge 89.0.774.76, which are the latest versions in the Stable channel.

This vulnerability is believed to be the same one used by Dataflow Security's Bruno Keith and Niklas Baumstark at Pwn2Own 2021, where the researchers exploited Google Chrome and Microsoft Edge.

Zero Smash Player Twitter

getting popped with our own bugs wasn't on my bingo card for 2021. not sure it was too smart of Google to add that regression test right away... https://t.co/e0RUlmbxRK

— Niklas B (@_niklasb) April 12, 2021

Google is expected to release Chrome 90 to the Stable channel tomorrow, and we will have to see if the upcoming version includes a fix for this zero-day RCE vulnerability.

Generation Zero Twitter

BleepingComputer has contacted Google about the zero-day but has not received a reply as of yet.

Related Articles:

Google uses cookies and data to:
  • Deliver and maintain services, like tracking outages and protecting against spam, fraud, and abuse
  • Measure audience engagement and site statistics to understand how our services are used
If you agree, we’ll also use cookies and data to:
  • Improve the quality of our services and develop new ones
  • Deliver and measure the effectiveness of ads
  • Show personalized content, depending on your settings
  • Show personalized or generic ads, depending on your settings, on Google and across the web
For non-personalized content and ads, what you see may be influenced by things like the content you’re currently viewing and your location (ad serving is based on general location). Personalized content and ads can be based on those things and your activity like Google searches and videos you watch on YouTube. Personalized content and ads include things like more relevant results and recommendations, a customized YouTube homepage, and ads that are tailored to your interests.Zero Twitter

Click “Customize” to review options, including controls to reject the use of cookies for personalization and information about browser-level controls to reject some or all cookies for other uses. You can also visit g.co/privacytools anytime.