After all what does "significantly more effort" mean? Yes there is raising the bar but do we know if _in practice_ those countermeasures make any sort of meaningful difference especially considering that a lot of the countermeasures can be defeated (ASLR -> information leaks, sandboxing -> hitting the kernel). Taking into account that the vast majority of cutting-edge offensive security research happens behind closed doors, the public has almost no visibility in this area.
If a South Korean teenager can break Google Chrome at his leisure, what about more resourceful adversaries that do not even have to be nation states?
Of course corporations like to talk exactly this kind of talk, raising the bar, "significantly more effort", better-than-the-rest and so on, since it lets them harbor the illusion that they're doing something but another way of looking at the data is this:
Google Chrome was first released in 2008. 8 years later, and it is _still_ remotely exploitable by solo individuals or small teams that release their exploits for not-a-lot-of-money. I'm singling out Chrome here because apparently it's the browser with the highest score in the OP report, but of course every other browser has the same issues.
Collectively, since the inception of the web, we have not had a browser that wasn't remotely exploitable. Can we do better? Judging from other critical software, it appears that we can.
Why haven't we??
Partly because the necessary processes haven't been there and I hope that the Mudge project will change that.
Let's move beyond smoke & mirrors to actual security.
I would like to be proven wrong however, if not by them, then by others.
>every successful attack at Pwn2Own 2016 achieved SYSTEM or ROOT privileges, which has never happened at the event before.
Source: http://venturebeat.com/2016/03/18/pwn2own-2016-chrome-edge-a...