Pwn2own day one: Safari, IE8 fall, Chrome unchallenged
arstechnica.com
arstechnica.com
then later
> One possible reason for this is that Google published a Chrome update yesterday, closing at least 24 security flaws. The would-be Chrome attacker may have been depending on one of these flaws to attack the browser.
I thought the configuration was frozen last week. Was that only for Apple? On first read, this seems like a faulty conclusion based on the earlier statement.
Which means even though Apple patched the 60 vulnerabilities the researcher used a one that was not known and thus not patched.
Note that unless things have changed (something which I can find no evidence for,) snow leopard still lags behind windows and linux in its ASLR, in that it doesnt randomise all the key parts of the kernel. Hopefully this will be fixed in lion.
http://www.theregister.co.uk/2009/08/29/snow_leopard_securit...
https://secure.wikimedia.org/wikipedia/en/wiki/Address_space...
EDIT: although apparently, as ever, the community comes to the rescue. Stefan Esser presents steps to randomise dyld's address space yourself: http://antid0te.com/antid0te-for-snow-leopard-rebasing-dyld....
"The third browser to be tested was scheduled to be Chrome. However, the contestant registered to attempt the attack did not show up, so the browser remains unbeaten."