Google Chrome adopts Windows 10 security feature


San Francisco, May 5 (IANS): To protect the memory stack from attackers, Google revealed that its Chrome 90 has adopted a new Windows 10 security feature called "Hardware-enforced Stack Protection".

Hardware-enforced Stack Protection, which Microsoft previewed in March 2020, is designed to protect against return-oriented programming (ROP) malware attacks, by using CPU hardware to protect an application's code while running inside the CPU memory.

The added protection is enabled in Chrome 90 on Windows 20H1 with December update or later and on Intel 11th Gen or AMD Zen 3 CPUs, which feature Control-flow Enforcement Technology (CET), ZDNet reported.

For several years, Intel and Microsoft have been working on CET to thwart ROP attacks, which can bypass existing memory-exploit mitigations to install malware, the report said.

CET introduced "shadow stacks", which are used exclusively for control transfer operations. These shadow stacks are isolated from the data stack and protected from tampering, it added.

Google's Chrome platform security team warns that the shadow stack might cause problems for some software loaded into Chrome.

"CET improves security by making exploits more difficult to write. However, it may affect stability if the software that loads itself into Chrome is not compatible with the mitigation," the Chrome security team said.

Google, however, has also provided details for developers who need to debug a problem in Chrome's shadow stack.

Developers can see which processes have Hardware-enforced Stack Protection enabled in Windows Task Manager, the report said.

Google describes ROP attacks as where "attackers take advantage of the process's code, as that must be executable".

 

  

Top Stories


Leave a Comment

Title: Google Chrome adopts Windows 10 security feature



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.