frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

A privilege escalation from Chrome extensions (2023)

https://0x44.xyz/blog/cve-2023-4369/
65•deryilz•1d ago

Comments

Briannaj•1d ago
This is worth more than 10k imo. But I guess since you have to have an extension installed maybe that's why?
curiousObject•1d ago
Agree.

The only permission the extension needed was “downloads, which normally only allows an extension to download and search for user files, not read or write to them”

That’s not an unusual permission for an attractive but safe sounding extension, for example an extension to download all images from a page

$100k at least?

The value of this to bad guys could be up to millions

SchemaLoad•1d ago
Well the author decided to sell the bug to Google rather than to criminals so I guess it was deemed a good value. By selling it to Google you get to write a nice blog post you can show to future employers and you don't have to involve yourself in crime. So the payout needed is a lot less than what hackers might be offering.
DaSHacka•1d ago
I have to wonder how many people mix-and-match.

Like, does a 6th or 7th blog post really matter, versus getting a large payout?

No rule that says you can't do both, or only disclose+publish the more 'impressive' of your exploits.

tim1994•1d ago
Interesting read for sure! This is about ChromeOS though, Chrome on other platforms was not affected.
rvz•20h ago
> For example, Google awarded $10,000 to a bug report which showed that extensions could read local files by screenshotting them. But there are more dangerous things than file reads.

I think this researcher got scammed without knowing it.

Google paid $10k for this bug despite billions of users using Chrome and there are plenty of brokers that will pay much more than that. (e.g. Zerodium)

They should have sold it as a 0day on the black market for more that $250k.

deryilz•20h ago
Keep in mind it's a ChromeOS only bug. They regularly get less money, because not that many people use ChromeOS.
postalrat•16h ago
Don't a lot of schools use chromebooks?
deryilz•16h ago
True, but I don't think K12 students are the main targets of these big gray-hat companies that buy bugs for a lot of money.
rxliuli•19h ago
Your journey of discovery is really cool.

Agents Aren't Juniors, They Are Amnesiac Spies

https://avdi.codes/agents-arent-juniors-they-are-amnesiac-spies/
1•kiyanwang•27s ago•0 comments

Agentic book – The Human Algorithm [pdf]

https://github.com/JayDoubleu/agentic-book/blob/main/book/pdf/the-human-algorithm-digital.pdf
1•JayD0ubleu•37s ago•0 comments

Philips Ease

https://thefoggiest.dev/2025/05/29/philips-ease
1•ingve•3m ago•0 comments

Haskell Weekly Issue 474

https://haskellweekly.news/issue/474.html
1•amalinovic•7m ago•0 comments

Intel Shows Off Professional Battlemage Cards

https://www.semiaccurate.com/2025/05/27/intel-shows-off-professional-battlemage-cards/
1•walterbell•10m ago•0 comments

Ivey Business School's Value Investing Program – Adam Waterous [video]

https://www.youtube.com/watch?v=SmdAWuGsWH0
1•chenchenchen•22m ago•1 comments

Top math software platform still offline following ransomware attack

https://www.techradar.com/pro/security/top-math-software-and-services-platform-still-offline-following-ransomware-attack
1•howisthatposs•22m ago•0 comments

Show HN: OpenDeRisk – open-source intelligent app risk manager

https://github.com/derisk-ai/OpenDerisk
1•jamie-vesoft•26m ago•0 comments

China extends its reach into the Solar System with launch of asteroid mission

https://arstechnica.com/science/2025/05/china-extends-its-reach-into-the-solar-system-with-launch-of-asteroid-mission/
2•rbanffy•31m ago•1 comments

Elon Musk exits US Government after breaking with Trump on tax bill

https://www.theguardian.com/technology/2025/may/29/elon-musk-announces-exit-from-us-government-role-after-breaking-with-trump-on-tax-bill
5•dagss•31m ago•0 comments

Redesigning the Initial Rust Bootstrap Sequence

https://blog.rust-lang.org/inside-rust/2025/05/29/redesigning-the-initial-bootstrap-sequence/
2•ingve•34m ago•0 comments

NI3

https://en.wikipedia.org/wiki/Nitrogen_triiodide
1•keepamovin•40m ago•2 comments

Rethinking African edtech: Why AI alone won't be enough

https://techcabal.com/2025/05/28/rethinking-african-edtech/
1•MarcoDewey•45m ago•0 comments

Show HN: Flags Quiz – Flags of All World Countries

https://flags-quiz.com/
1•artiomyak•48m ago•0 comments

Saying Bye to Glitch

https://pketh.org/bye-glitch.html
2•tobr•53m ago•0 comments

We built a distributed cache for S3

https://clickhouse.com/blog/building-a-distributed-cache-for-s3
1•samaysharma•54m ago•0 comments

Read Frog – Open-Source AI Language Translator and Teacher in Browser

https://github.com/mengxi-ream/read-frog
1•mengxi-ream•55m ago•1 comments

The weight of an entire industry trying to convince you that you're inadequate

https://buttondown.com/monteiro/archive/how-to-survive-the-weight-of-an-entire-industry/
3•tobr•56m ago•0 comments

Show HN: Warden – A Native (and Free) AI Chat App for macOS

https://karatsidhu.gumroad.com/l/warden
2•skarat•1h ago•0 comments

What's cooking on Sourcehut? Q2 2025

https://sourcehut.org/blog/2025-05-29-whats-cooking-q2/
1•Tomte•1h ago•0 comments

STOC Best Paper Award: How to Find the Shortest Path – Faster

https://www.mpi-inf.mpg.de/news/detail/stoc-best-paper-award-how-to-find-the-shortest-path-faster
1•mfiguiere•1h ago•0 comments

Cyber Resilience Act and Open Source: What Maintainers Need to Know [video]

https://www.youtube.com/watch?v=DLxZdU8kzxM
2•lis•1h ago•0 comments

Glacier collapse buries most of Swiss village

https://www.bbc.com/news/articles/cnv1evn2p2vo
6•hubraumhugo•1h ago•1 comments

Show HN: Entropy – Sharing screen is scary in SaaS age

https://entropysec.io/
2•RazCo•1h ago•0 comments

Emergency We Cannot Feel: On the Psychological Unreadiness for American Collapse

https://www.notesfromthecircus.com/p/the-emergency-we-cannot-feel-on-the
7•cmurf•1h ago•2 comments

Statically typed languages are like Elephants

1•pyeri•1h ago•0 comments

Raw.githubusercontent.com – How to authenticate and see headers with info?

https://github.com/orgs/community/discussions/160828
1•jarofgreen•1h ago•0 comments

No iOS 19: Apple Going Straight to iOS 26

https://www.macrumors.com/2025/05/28/apple-ios-26/
1•Tomte•1h ago•0 comments

Show HN: I made an AI prompt manager to stop rewriting the same prompts

https://www.echostash.app/
1•debeast•1h ago•0 comments

Front End Engineering Team Working Style Guide

https://github.com/vishwajeetv/frontend-engineering-team-working-style-guide
1•vishwajeetv•1h ago•0 comments