YoVDO

Escaping Modern Web-Based App Sandboxes - Site Isolation Vulnerabilities

Offered By: Black Hat via YouTube

Tags

Browser Security Courses Sandboxing Courses Remote Code Execution Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the vulnerabilities in Chrome's process isolation and Site Isolation security features in this 36-minute Black Hat conference talk. Delve into an exploitation method for Chrome on Android that enables Universal Cross-Site Scripting (UXSS) through renderer Remote Code Execution (RCE). Examine how this exploit, while limited in Chrome's threat model, can be leveraged in various Chromium-based applications like libcef and webview. Investigate security issues in PC-based libcef applications, pre-installed mobile browsers, and Android Webview applications that allow attackers to escape the Chrome sandbox from a compromised renderer. Learn about potential malicious actions, including remote code execution, silent app installation, and user data theft. Gain insights from senior security researchers at Tencent Security Xuanwu Lab on the limitations of current Site Isolation defense strategies and their implications for web-based application security.

Syllabus

The Hole in Sandbox: Escape Modern Web-Based App Sandbox From Site-Isolation Perspective


Taught by

Black Hat

Related Courses

Introduction to Cyber Security
Uttarakhand Open University, Haldwani via Swayam
The Complete Cyber Security Course : Network Security!
Udemy
The Beginners 2024 Cyber Security Awareness Training Course
Udemy
Modern Browser Security Reports
Pluralsight
JavaScript Security Part 1
Infosec via Coursera