Every time Tavis Ormandy and Google's Project Zero publish something related to a bug, the Web trembles. They are very good at their work, and relentless when it comes to publishing information, a detail that has caused significant friction with several companies, especially with Microsoft. But this time it's the turn of Redmond's Offensive Security Research team, which has just discovered a bug in the Google Chrome browser that allows an attacker to execute code remotely.
The first major clash between Google's Project Zero and Microsoft occurred in January 2015. The Mountain View team gives a 90-day window before publishing details related to any bug, but Redmond has explained more than once that those 90 days are not always enough, and if researchers proceed with publication anyway, all they achieve is exposing users. The discussion quickly polarized, but the average user's opinion is that both companies are wrong for multiple reasons. Microsoft's quality control is terrible, and there is no better proof than its system-destroying hotfixes. On the other side, Android has more holes than a sieve, and official patches reach a minimal percentage of devices.
Making public statements has its effect, but in Microsoft they seem to have concluded that it is better to pay back in kind, and their Offensive Security Research team began concentrating efforts on Google Chrome. The first result is CVE-2017-5121, a vulnerability that can enable remote code execution when the user is directed to a specially crafted page. The final impact depends on execution privileges, but the installation of malicious programs and data theft is not ruled out. To discover the bug, Microsoft used ExprGen, a JavaScript-based fuzzer designed by the same group that created Chakra, the JavaScript engine found in Edge.
The official publication contains all the relevant details of the case, however, the most interesting part is at the end. Microsoft reported CVE-2017-5121 on September 14 with the corresponding exploit, to which Google assigned a reward of $7,500. Other lower-profile bugs (reported but without exploit) raised the sum to $15,837. Google decided to match the reward, and the $30,000 were donated to the Denise Louise Education Center, an organization chosen by Microsoft. At Redmond, they still question the decision to publish data about bugs before patches reach users, but despite the differences, it is good to know that the skill of these titans can help someone else.