FF Sandbox Escape
googleprojectzero.blogspot.com
googleprojectzero.blogspot.com
> As I’m a Chromium committer as well as an owner of the Windows sandbox I realized I might be better placed to fix this than Mozilla who relied on our code.
So I would say it's a security critical bug a sandbox escape and a building blog for an exploit but not a exploit by itself.
Anyway it's sill a security vulnerability.
Because as someone who is highly skeptical of Google's motives a lot of the time, that just seems like a batty take for anyone who is familiar with their work.
The only reason that deadline exists is because many vendors have had a long history of taking advantage of researchers who agree to embargo details of their work while the vendors work on a fix. Bugs were going unfixed for years.
It has been my observation that this strategy only partially worked. The main thing that happened is that vendors now won’t sit on Google reported vulns, because they know Google are not bluffing, but they’re still generally happy to take their sweet time if the report comes from someone else. I know of some companies who put PZ bugs in a special queue to fast track them.
I think it has done a little bit in terms of setting norms for shorter disclosure timelines though.
Project zero posts:
Google: 24
Apple: 28
Microsoft: 36
I was curious, so I poked around the project zero bug tracker to try to find ground truth about their bug reporting: https://bugs.chromium.org/p/project-zero/issues/list For all issues, including closed:
product=Android returns 81 results
product=iOS returns 58
vendor=Apple returns 380
vendor=Google returns 145 (bugs in Samsung's Android kernel,etc. are tracked separately)
vendor=Linux return 54
To be fair, a huge number of things make this not an even comparison, including the underlying bug rate, different products and downstream Android vendors being tracked separately. Also, # bugs found != which ones they choose to write about.