A Russian security researcher has earned himself a tidy $60,000 by demonstrating how he could waltz past the security sandbox in Google’s Chrome browser to run unauthorised code on fully-patched Windows 7 computers.
Sergey Glazunov uncovered a remote code execution vulnerability in Chrome, that could be used by malicious hackers and cybercriminals to install and run code on innocent users’ computers, just by them visiting a website.
Glazunov, who is no stranger to reporting bugs in Chrome, won his substantial reward as part of the Pwnium competition run by Google at the CanSecWest conference in downtown Vancouver.
Sundar Pichai, a senior vice-president at Google, wrote on Google+ that his developers were “working fast on a fix” that would be pushed out as an automatic security update to Chrome users.
Google announced last month that they were offering a gobsmacking grand total of $1 million in rewards for those who uncovered security holes in Chrome.
At the time of writing, a hefty $940,000 remains in the Pwnium prize fund.