Security News > 2020 > August > Google Awards $10,000 for Remote Code Execution Vulnerability in Chrome

Google Awards $10,000 for Remote Code Execution Vulnerability in Chrome
2020-08-12 13:02

Google this week announced that an update for Chrome 84 includes 15 security patches, including for a serious vulnerability for which the tech giant awarded a $10,000 bug bounty.

This vulnerability is CVE-2020-6542, a high-severity use-after-free bug in ANGLE, the Chrome component responsible for translating OpenGL ES API calls to hardware-supported APIs available for the operating system.

Discovered by Piotr Bania of Cisco Talos, the remote code execution vulnerability is easy to exploit, as the attacker only needs to set up a website containing malicious code that would be triggered upon user visit.

Google awarded the security researcher a $10,000 bug bounty reward for reporting this vulnerability.

Google has yet to provide information on the bug bounties paid to the reporting researchers.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/8rqD0hR0X2o/google-awards-10000-remote-code-execution-vulnerability-chrome

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-09-21 CVE-2020-6542 Use After Free vulnerability in multiple products
Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-416
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 996 4895 2855 1622 10368