ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google and Mozilla fixed issues exploited at 2020 Tianfu Cup contest

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-16016
Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially p

Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

NVD description · AI analysis pending
9.6<1%
  • google chrome
CVE-2020-26950
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition.

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

NVD description · AI analysis pending
8.842% PoC ×2
  • mozilla firefox
  • mozilla firefox esr
  • mozilla thunderbird
Full article216 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 11, 2020

Mozilla and Google have already fixed the critical flaws in Firefox and Chrome exploited by bug bounty hunters at 2020 Tianfu Cup hacking contest.

Mozilla and Google have already addressed the critical Firefox and Chrome vulnerabilities that were recently exploited by white hat hackers at the 2020 Tianfu Cup hacking contest.

The vulnerability in Chrome exploited by hackers at the 2020 Tianfu Cup, tracked as CVE-2020-16016, is an inappropriate implementation issue that resided in the base component. Google addressed the flaw with the release of Chrome 86.

The CVE-2020-16016 flaw, along with the CVE-2020-26950 issue, was exploited by a team named “360 Enterprise Security and Government and (ESG) Vulnerability Research Institute,” which is part of the Chinese tech giant Qihoo 360 that won the competition. The team earned $744,500 of the total $1,210,000 jackpot.

The Firefox vulnerability, tracked as CVE-2020-26950, is related to write side effects in MCallGetProperty opcode not being accounted for.

“In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition,” reads the advisory published by Mozilla.

Mozilla addressed the issue with the release of Firefox 82.0.3, Firefox ESR 78.4.1 and Thunderbird 78.4.2.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, 2020 Tianfu Cup)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/110773/security/google-mozilla-2020-tianfu-cup.html