Chrome Virtualization

Am I right in saying Chrome effectively uses the same protected mode as Internet Explorer uses when UAC is on?

Thanks,
Craig.

Pretty much, yes, it runs as a series of low integrity processes which will dramatically limit the access levels it has to other parts of the system exactly the same as IE.
 
What reports have you heard of using exploits to penetrate past the sandbox?

http://uk.youtube.com/watch?v=QJhcGRJEQ2w, for starters - it's the WebKit carpetbomb bug (that's been fixed in WebKit for ages).

On the other hand the worst it can do, unless you've disabled UAC or blindly hit Continue/Allow, is mess up your own stuff - but that's the worst that can happen with "insecure" Firefox/Opera/IE without protected mode.
 
http://uk.youtube.com/watch?v=QJhcGRJEQ2w, for starters - it's the WebKit carpetbomb bug (that's been fixed in WebKit for ages).

On the other hand the worst it can do, unless you've disabled UAC or blindly hit Continue/Allow, is mess up your own stuff - but that's the worst that can happen with "insecure" Firefox/Opera/IE without protected mode.

Not sure if I was too late, or I got an update just after the exploit was released but the download exploit never worked for me, only the crash one worked.
 
Back
Top Bottom