Google squashes 10 Chrome bugs as $100K Pwn2Own hacking prize looms
Google on Monday patched 10 vulnerabilities in Chrome, just two days before the start of Pwn2Own, a hacking contest that has $100,000 in prize money waiting for the first researcher to crack the browser.
In an update Monday for the Windows and Linux versions—Google patched the OS X edition on Friday—the company fixed 10 flaws, six of them marked as “high,” the second-most-serious threat ranking. Of the remaining bugs, three were pegged as “medium” and one as “low.”
Monday’s patches follow a larger batch issued Feb. 21, and further harden Chrome as it faces Pwn2Own, the hacking challenge that kicks off March 6 at the CanSecWest security conference in Vancouver, British Columbia.
Google has contributed money to Pwn2Own’s prize pool, which includes a $100,000 award to the first researcher who hacks the current version of Chrome on Windows 7.
Pwn2Own will put a record $560,000 on the line over its three days, with prizes awarded on a sliding scale aligned with the anticipated difficulty of each hack. The first researcher to successfully exploit Internet Explorer 10 (IE10) on Windows 8 will receive $100,000, for example, while the first able to crack Firefox on Windows 7 will get $60,000.
IE9, Safari on OS X, Adobe Flash and Adobe Reader, and Oracle Java will also pose as targets.
Of the 10 vulnerabilities patched Monday, four were reported by three independent researchers, who received a total of $5,000 from Chrome’s bug bounty program. So far this year, Google has paid out $15,500 in bounties.
Other browser makers have also recently patched their software, perhaps with an eye on Pwn2Own.
Three weeks ago, Microsoft updated all versions of IE, including IE9 and IE10—both Pwn2Own targets—with 14 patches. Twelve of those were rated “critical” by Microsoft for IE9, while five were tagged the same for IE10.
On Feb. 19, Mozilla released Firefox 19, patching 13 vulnerabilities, 10 of which were labeled critical.
Also on Monday, Google updated Chrome for Apple’s iOS operating system to version 25, matching the moniker of the desktop edition. According to a brief release note, Chrome 25 for iOS will also sport new search features “over the coming days” that show the search string in the browser’s “omnibox,” Google’s term for the address field, and let users refine queries from the search results page.
Chrome for iOS can be downloaded free of charge to an iPhone, iPad or iPod Touch from Apple’s App Store.
Chrome for iOS is currently No. 94 on the App Store’s iPhone free-app download list, and No. 50 on the corresponding iPad list.
Chrome 25 on iOS now lets users share a page via Messages, Apple’s for-free replacement for paid texting.