Microsoft Edge? Google's Project Zero team has published several details that help circumvent a major security technique in Edge.
Let's see what the problem is:
Arbitrary Code Guard (ACG), released with the Windows 10 Creators Update to help prevent web-based attacks that try to load malicious code into memory. This technique ensures that memory only accepts properly signed code.
However, as Microsoft explains, the Just-in-Time (JIT) compilers used in modern web browsers create a problem for ACG. JIT compilers convert JavaScript into native code, which is unsigned.
So to ensure that JIT compilers continue to work even when ACG is enabled, the company's developers separated Microsoft Edge's JIT into a separate process that runs in its own isolated sandbox.
But that's where researchers from Google's Project Zero came in. The researchers found that there is a problem in the way the JIT process writes executable data to the content.
The 'ACG bypass using UnmapViewofFile' allows a content process to predict which address of a JIT process can call VirtualAllocEx(), and the content process is preparing to "allocate a writable memory region at the same address of the JIT server for a soon-to-be-executed executable."
Google reported the issue to Microsoft in mid-November and published details of the exploit yesterday, as the 90-day deadline passed.
Microsoft confirmed the ACG bypass at some point in its February Patch Tuesday. The company apparently intended to fix the issue by then, but found it to be a bit "more complicated" than it initially thought.
So the solution for a secure Microsoft Edge is expected to be released with the March Patch Tuesday.
Microsoft Edge; watch out until next month
📧
Subscribe to the SecNews Newsletter
