Google squashes 10 Chrome bugs as $100K Pwn2Own hacking prize looms
Also releases Chrome 25 for Apple's iPhone and iPad, promises search improvements
Computerworld - Google today patched 10 vulnerabilities in Chrome, just two days before the start of Pwn2Own, a hacking contest that has $100,000 in prize money waiting for the first researcher to crack the browser.
In an update Monday for the Windows and Linux versions -- Google patched the OS X edition on Friday -- the company fixed 10 flaws, six of them marked as "high," the second-most-serious threat ranking. Of the remaining bugs, three were pegged as "medium" and one as "low."
Today's patches follow a larger batch issued Feb. 21, and further harden Chrome as it faces Pwn2Own, the hacking challenge that kicks off March 6 at the CanSecWest security conference in Vancouver, British Columbia.
Google has contributed money to Pwn2Own's prize pool, which includes a $100,000 award to the first researcher who hacks the current version of Chrome on Windows 7.
Pwn2Own will put a record $560,000 on the line over its three days, with prizes awarded on a sliding scale aligned with the anticipated difficulty of each hack. The first researcher to successfully exploit Internet Explorer 10 (IE10) on Windows 8 will receive $100,000, for example, while the first able to crack Firefox on Windows 7 will get $60,000.
IE9, Safari on OS X, Adobe Flash and Adobe Reader, and Oracle Java will also pose as targets.
Of the 10 vulnerabilities patched today, four were reported by three independent researchers, who received a total of $5,000 from Chrome's bug bounty program. So far this year, Google has paid out $15,500 in bounties.
Other browser makers have also recently patched their software, perhaps with an eye on Pwn2Own.
Three weeks ago, Microsoft updated all versions of IE, including IE9 and IE10 -- both Pwn2Own targets -- with 14 patches. Twelve of those were rated "critical" by Microsoft for IE9, while five were tagged the same for IE10.
On Feb. 19, Mozilla released Firefox 19, patching 13 vulnerabilities, 10 of which were labeled critical.
Also on Monday, Google updated Chrome for Apple's iOS operating system to version 25, matching the moniker of the desktop edition. According to a brief release note, Chrome 25 for iOS will also sport new search features "over the coming days" that show the search string in the browser's "omnibox," Google's term for the address field, and let users refine queries from the search results page.
Chrome for iOS can be downloaded free of charge to an iPhone, iPad or iPod Touch from Apple's App Store.
Chrome for iOS is currently No. 94 on the App Store's iPhone free-app download list, and No. 50 on the corresponding iPad list.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed . His email address is firstname.lastname@example.org.
- IE6: Retired but not dead yet
- Chrome users won't give up, keep pressing Google to restore old-style new tab page
- Google quashes 31 vulnerabilities, restores Metro mode 'steppers' with Chrome 34
- Firefox's UI face-lift on track for April debut
- Ex-Mozilla engineer blames Microsoft's rules for Metro Firefox's death
- Mozilla patches 20 Firefox flaws, plugs Pwn2Own holes
- Google reverses field, promises to restore Chrome's scrollbar arrows
- Update: Google ships Chrome 33, patches 28 bugs
- Mozilla's top exec defends in-Firefox ads, revenue search
- Mozilla taps in-Firefox ads as it searches for more revenue
Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.
- 2013 Cyber Risk Report The "Cyber risk report 2013 Executive summary" presents the major findings of HP Security Research's comprehensive dive into today's cyber vulnerability and threat...
- Why You Need a Next-Generation Firewall This white paper explores the reasons for implementing next-generation (NG) firewalls and lays out a path to success for overburdened IT organizations.
- Path Selection Infographic Path Selection Infographic
- Hyperconvergence Infographic A wide range of observers agree that data centers are now entering an era of "hyperconvergence" that will raise network traffic levels faster...
- Cloud Knowledge Vault Learn how your organization can benefit from the scalability, flexibility, and performance that the cloud offers through the short videos and other resources...
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users? All Malware and Vulnerabilities White Papers | Webcasts