Hacker News new | ask | show | jobs
by hardware2win 1154 days ago
Anecdote:

Ive tested a two or three years old Chrome version with JIT compiler vulnerability and guess what - on empty Linux vm it managed to escape chrome and execute code

Meanwhile on Windows with Crowdstrike software installed Chrome just showed some error message about mem. access

Im not sure who handled that attack - was it Windows or Crowdstrike, but eitherway Ive been impressed

3 comments

I can pretty much guarantee that the Windows kernel stopped unallowed memory access from chrome to outside apps.
Under OpenBSD pledge and unveil would send that Chromium instance SIGABRT'ed. Your parent comment it's utterly wrong.
With or without SELinux enabled?
Idk, that was fresh instal