{"id":345296,"date":"2025-08-18T05:10:00","date_gmt":"2025-08-18T12:10:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/es\/?p=393494"},"modified":"2025-08-18T05:10:14","modified_gmt":"2025-08-18T12:10:14","slug":"discover-a-vulnerability-in-the-architecture-of-chrome-and-google-rewards-him-with-250000-dollars","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/discover-a-vulnerability-in-the-architecture-of-chrome-and-google-rewards-him-with-250000-dollars\/","title":{"rendered":"Discover a vulnerability in the architecture of Chrome and Google rewards him with 250,000 dollars"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Google has awarded a historic reward of $250,000 to the security researcher known as Micky for discovering a critical vulnerability in the architecture of the Chrome browser. <strong>This vulnerability made it easier for malicious websites to escape Chrome&#8217;s sandbox protection, allowing arbitrary code execution on victims&#8217; systems.<\/strong><\/p>\n\n\n<h2 class=\"wp-block-heading\">A historic reward<\/h2>\n\n\n<p class=\"wp-block-paragraph\">The failure was due to an error in Chrome&#8217;s Inter-Process Communication system, particularly within the IPCZ transport mechanism. <strong>According to the details provided, the error was in the Transport::Deserialize function, where the system did not adequately validate the header.destination_type parameters before creating transport objects<\/strong>. This allowed a malicious rendering process to manipulate this parameter to impersonate a privileged broker process.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The required attack vector was a multi-step process in which a compromised renderer sent manipulative messages to take control of the browser process resources.<strong> The proof of concept of the exploit demonstrated the ability to bypass the sandbox by duplicating handles of privileged browser processes, which included full permissions to execute system commands<\/strong>.<\/p>\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Google Chrome \u30a2\u30cb\u30e1 #3\u300c\u304c\u3093\u3070\u308c\uff01\u304f\u308d\u30fc\u3080  &quot;\u3086\u30fc\u3056\u30fc\u3055\u3093\u305c\u3063\u305f\u3044\u307e\u3082\u308b\uff01\u306e\u5dfb&quot;\u300d\" width=\"840\" height=\"473\" src=\"https:\/\/www.youtube.com\/embed\/nMF3nLV-m24?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n<p class=\"wp-block-paragraph\">The decision to grant such a high reward reflects not only the sophistication of the exploit but also Google&#8217;s commitment to incentivizing security research, especially in critical areas of its browser. <strong>The vulnerability was responsibly disclosed on April 22, 2025, and Google&#8217;s security team, led by Alex Gough, implemented fixes in May 2025<\/strong>. These included the removal of transitive trust from transports and the implementation of stricter validation of the reliability of endpoints within the IPCZ system.<\/p>\n\n\n<p class=\"wp-block-paragraph\">This event underscores <strong>the importance of collaboration between security researchers and technology companies to maintain the integrity and security of digital platforms<\/strong>.<\/p>\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Google\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/b03d4f44-9b32-11e6-9f73-00163ed833e7\/793885015\/google-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/google.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Google has awarded a historic reward of $250,000 to the security researcher known as Micky for discovering a critical vulnerability in the architecture of the Chrome browser. This vulnerability made it easier for malicious websites to escape Chrome&#8217;s sandbox protection, allowing arbitrary code execution on victims&#8217; systems. A historic reward The flaw was due to an error in Chrome&#8217;s Inter-Process Communication system, particularly within the IPCZ transport mechanism. According to the details provided, the error was in the Transport::Deserialize function, where the system did not properly validate the header.destination_type parameters before [&hellip;]<\/p>\n","protected":false},"author":9318,"featured_media":345297,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[15192,2095,7978,1068,13665],"usertag":[],"vertical":[],"content-category":[7176],"class_list":["post-345296","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-alex-gough","tag-chrome","tag-exploit","tag-google","tag-vulnerabilidad","content-category-seguridad-privacidad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/345296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9318"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=345296"}],"version-history":[{"count":2,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/345296\/revisions"}],"predecessor-version":[{"id":345303,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/345296\/revisions\/345303"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/345297"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=345296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=345296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=345296"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=345296"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=345296"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=345296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}