Google builds stronger Flash sandbox in Chrome
Windows XP version now also includes anti-exploit technology
Computerworld - Google today announced it had wrapped up work on a stronger Flash sandbox in the Windows version of Chrome, and would soon ship the same for its OS X browser.
Chrome 21, which launched July 31, completed efforts to ditch the aged NPAPI (Netscape Plugin Application Programming Interface) Flash plug-in for one built to Google's own PPAPI (Pepper Plugin Application Programming Interface) standard.
By porting Flash Player to PPAPI, Google's engineers were able to stuff the Adobe plug-in into a "sandbox" as robust as the one that protects Chrome itself.
"Windows Flash is now inside a sandbox that's as strong as Chrome's native sandbox, and dramatically more robust than anything else available," Justin Schuh, a Chrome engineer, in a post to the Chromium blog Wednesday.
A sandbox is an anti-exploit technology that isolates processes on the computer, preventing or at least hindering malware from letting hackers exploit an unpatched vulnerability, escalate privileges and push their attack code onto the machine.
Chrome was the first to sandbox Flash Player: Google shipped a "stable" build of the browser in March 2011 with a Windows sandbox for Flash. In May 2012, Adobe issued a sandboxed Flash plug-in for Mozilla's Firefox, although the open-source browser maker has struggled to diagnose a higher-than-usual number of Flash crashes since then.
Previously Chrome's Flash sandbox was only available on Windows Vista and Windows 7, but with Chrome 21 and the move to PPAPI, Google was able to extend coverage to Windows XP.
"[That's] critical given the absence of OS support for security features like ASLR and integrity levels [in Windows XP]," Schuh said.
Schuh claimed that Chrome is run by about 100 million Windows XP users.
According to Web analytics company Net Applications, Windows XP powered 46.6% of all Windows PCs that went online in July, a slightly larger share than the quickly-gaining Windows 7.
The port of Flash to PPAPI will reduce Flash crashes by 20%, and prepares Chrome for its debut on Windows 8, the upgrade Microsoft plans to start selling Oct. 26.
"Because PPAPI doesn't let the OS bleed through, it's the only way to use all Flash features on any site in Windows 8 Metro mode," Schuh wrote, referring to the tile-based environment that, along with a traditional desktop, comprises Windows 8.
Google added a Metro version of Chrome to the rougher "dev" channel in mid-June.
Although a fully-sandboxed Flash Player plug-in is yet not included in Chrome on OS X, Schuh said that the team "hope[s] to ship it soon."
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, on Google+ or subscribe to Gregg's RSS feed
. His email address is gkeizer@computerworld.com.
See more by Gregg Keizer on Computerworld.com.
Browser wars
- Mozilla to Firefox: 'Browser, heal thyself'
- Best case, Mozilla's Firefox for Windows 8 will ship in October
- Microsoft's browser auto-update pays off as IE10 share doubles
- Sued Opera designer fingers Mozilla's 'Search Tabs' as root of $3.4M claim
- Update: Opera slaps former designer with $3.4M lawsuit for spilling secrets
- As browsing goes mobile, Apple wins, Mozilla loses
- Mozilla pulls tracking trigger for Firefox 22, ignores ad industry attacks
- Mozilla refines Firefox's private browsing, patches 13 browser bugs
- Mobile's browser usage share jumps 26% in three months
- Mozilla again rejects porting Firefox to iOS
Read more about Application Security in Computerworld's Application Security Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Application Security eGuide In this eGuide, CIO and sister publications CSO and InfoWorld bring you news, opinions, research and advice regarding the risks that enterprises face...
- Case Study: Hospital Turns to Email Archiving Solution to Ensure Regulatory Compliances Read this case study to learn how a cloud-based email archiving solution enabled the hospital to meet government mandates and helps avoid thousands...
- Case Study: In-the-Cloud Email Service Replaces Three Point Products Read this case study for more information on a comprehensive in-the-cloud email service to help replace three point products.
- Case Study: Simplifying the Transition to Exchange 2010 with Email Management Solutions Read this case study to learn how a cloud-based email management solution greatly simplified the company's transition to Exchange 2010.
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with... All Application Security White Papers | Webcasts
