Geohot earned 150.000 dollars for the vulnerabilities he discovered on Chrome OS

Ο Geohot, is a hacker who became famous for jailbreaking Apple's iOS. Apparently the hacker has other interests Apple's mobile operating system. At Pwn2Own 2014, he proved his skills once again after winning $150.000 from Google for vulnerabilities he discovered in Chrome OS.
Geohot and the VUPEN team managed to win the biggest amounts in the hacker contest, Pwn2Own.
Read our previous publications for Pwn2Own 2014

Geohot

Η Google he says

Security Fixes and Rewards

Congratulations to geohot for an epic Pwnium competition win. Pinkie Pie provided a fascinating set of that will be rewarded through the Chrome VRP program. Moreover, one of the bugs exploited by VUPEN on Pwn2Own affected Chrome OS.

Congratulations to Geohot for the epic. Pinkie Pie gave us an exciting set of vulnerabilities that will be rewarded through Chrome VRP. In addition, one of the exploits of VUPEN for Pwn2Own that affects Chrome OS will be rewarded.

Below are all Chrome OS vulnerabilities that Google has rewarded for

  • [Like a cccc-hamp!!! $150,000] [351788] Persistent code on Chrome OS. Credit to geohot.
    • [351787] High CVE-2014-1705: Memory corruption in V8
    • [351796] low CVE-2014-1706: Command Injection in Crosh
    • [351811] High CVE-2014-1707: Path traversal issue in CrosDisks
    • [344051] Critical CVE-2014-1708: Issue with file persistence at boot
  • [$TBD] [352492] Sandboxed code execution and OOB write kernel. Credit to Pinkie Pie.
    • [351852] High CVE-2014-1710: Memory corruption in the GPU command buffer
    • [351855] High CVE-2014-1711: Kernel OOB write in GPU
  • [352374] High CVE-2014-1713: Use-after-free in Blink Bindings. Credit to VUPEN.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).