Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. This time it’s Microsoft that finds a critical bug in ChromeOS – onmsft.com

This time it’s Microsoft that finds a critical bug in ChromeOS – onmsft.com

Kareem Anderson Kareem Anderson
August 24, 2022
2 min read

Google has seemingly made it a sport to point out security issues with Windows as it purports to protect its Chrome users on the platform, but a new bug found by Microsoft put the onus back on Google to patch ChromeOS.

After years of proverbial finger wagging from Googles ‘Project Zero” bug bounty engineers who have found legitimate issues with Windows, Microsoft is firing back with a find of its own with the platform misusing strcpy().

According to the Chromium bug log, Security: ChromeOS cras D-Bus SetPlayerIdentity causes memory corruption severe enough for both Microsoft’s 365 Defender Research Team and Google to take action.

After locating a local memory corruption issue, we discovered the vulnerability could be remotely triggered by manipulating audio metadata. Attackers could have lured users into meeting these conditions, such as by simply playing a new song in a browser or from a paired Bluetooth device, or leveraged adversary-in-the-middle (AiTM) capabilities to exploit the vulnerability remotely.

In a more technical sense, from the command line, a heap-based buffer overflow could be triggered by passing a string of 128bytes to the dbus-send utility, the end result could be a simple Denial of Service or full-fledge Remote Code Execution.

After discovering the bug Microsoft tagged it with CVE-2022-2587 and with a Common Vulnerability Scoring System (CVSS) score of 9.8 out of 10 as far as critical efficacy.

Fortunately, this was all done back in April 2022 and has since been patched by Google and its ChromeOS team. In roughly a week, “the code was committed and, after several mergers, made generally available to users. We thank the Google team and the Chromium community for their efforts in addressing the issue,” Jonathan Bar Or of the Microsoft 365 Defender Research Team reported.

Despite being bitter business rivals, both Google and Microsoft lean on another to provide their customers with software and security solutions with Google needing Windows secure for Chrome browser users and now Microsoft needing Google’s help in keeping the Chromium project clear of threats, as it’s become the baseline for its reinvented Edge browser.

Share This Post:

Share this article:
Tags:
ChromeOS Google Microsoft
Previous Article Xbox head Phil Spencer “encouraged” by progress in Activision deal, still looking to acquire more – onmsft.com Next Article New Tales From the Borderlands video game coming to Xbox consoles this year – onmsft.com

Related Articles

Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS

April 4, 2026

New Ryzen 9 9950X3D2 loses performance on air cooling

April 4, 2026

Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense

April 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy