HomeSecurityA line of code in Windows puts popular browsers at risk

A line of code in Windows puts popular browsers at risk

Windows

It's common for Windows updates to cause various kinds of problems on users' devices , and they're constantly complaining about them. However, there's a chance that they could also cause problems with other applications .

As discovered by Google's Project Zero team last week, a single line of Windows code could cause problems with the sandboxing feature in Chromium , which powers the Chrome browser .

This is a security flaw that emerged after the release of the Windows 10 1903 update, which changed the way Windows manages access tokens for performing a process, thus allowing a potential attacker to slip out of Chrome's sandbox.

Access tokens contain the user account's security identifier (SID) and permissions associated with a process or thread. Each time a user logs in to their system, a new token is created that will be used for all processes that will occur during the login.

Chrome's sandboxing feature uses a feature called Restricted Token, which modifies a token to reduce the permissions it can have. However, the new update modified the Windows kernel code, creating a significant security hole.

Researcher James Forshawdemonstrated how an attacker can escape the sandbox in Chrome, Edge, and Firefox.

This vulnerability is quite serious, since if exploited by malicious actors it could affect millions of browsers around the world. These browsers include names like Opera and Firefox, which only use sandboxing.

Microsoft , the company said that the vulnerability would be difficult to exploit. The incident is a good example of how a small change to the operating system can cause security problems in other applications. How this change in the kernel code that led to the vulnerability occurred has not been discovered, but it is very likely due to some mishandling, as Forshaw said in a blog post.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS