Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2020-0981] You Won't Believe what this One Line Change Did to the Chrome Sandbox

Summary

This blog is about a vulnerability introduced in Windows 10 1903 which broke some of the security assumptions that Chromium relied on to make the sandbox secure. I’ll present how I used the bug to develop a chain of execution to escape the sandbox as used for the GPU Process on Chrome/Edge or the default content sandbox in Firefox. The exploitation process is also an interesting insight into the little weaknesses in Windows which in themselves do not cross a security boundary but led to a successful sandbox escape. This vulnerability was fixed in April 2020 as CVE-2020-0981.
CVE
CVE-2020-0981
Published
Collected

original ↗