logo

Evaluating Mitigations & Vulnerabilities in Chrome

ID: 6475f392-c4e9-5838-ac13-0b775f590769

STIX ID: report--6475f392-c4e9-5838-ac13-0b775f590769

Feed Name: Google Online Security Blog

Date Published: 2024-10-03

Date Updated: 2026-04-27

Author: Google

...
...

The Chrome Security Team outlines a threat model for browser code execution and a framework to evaluate attacker utility—emphasizing factors like reliability, low interaction, ubiquity, scriptability, stealth, and longevity—to guide mitigation priorities. It advocates incremental hardening (e.g., memory safety via Rust, sandboxing, detection like GWP-ASan) and the removal of escalation paths to raise attacker costs across diverse adversaries, arguing that even partial reductions in exploit utility meaningfully reduce overall user risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.