News
Discover a vulnerability in the architecture of Chrome and Google rewards him with 250,000 dollars
It is the largest amount ever granted in a reward of this kind

- August 18, 2025
- Updated: August 18, 2025 at 12:10 PM

Google has awarded a historic reward of $250,000 to the security researcher known as Micky for discovering a critical vulnerability in the architecture of the Chrome browser. This vulnerability made it easier for malicious websites to escape Chrome’s sandbox protection, allowing arbitrary code execution on victims’ systems.
A historic reward
The failure was due to an error in Chrome’s Inter-Process Communication system, particularly within the IPCZ transport mechanism. According to the details provided, the error was in the Transport::Deserialize function, where the system did not adequately validate the header.destination_type parameters before creating transport objects. This allowed a malicious rendering process to manipulate this parameter to impersonate a privileged broker process.
The required attack vector was a multi-step process in which a compromised renderer sent manipulative messages to take control of the browser process resources. The proof of concept of the exploit demonstrated the ability to bypass the sandbox by duplicating handles of privileged browser processes, which included full permissions to execute system commands.
The decision to grant such a high reward reflects not only the sophistication of the exploit but also Google’s commitment to incentivizing security research, especially in critical areas of its browser. The vulnerability was responsibly disclosed on April 22, 2025, and Google’s security team, led by Alex Gough, implemented fixes in May 2025. These included the removal of transitive trust from transports and the implementation of stricter validation of the reliability of endpoints within the IPCZ system.
This event underscores the importance of collaboration between security researchers and technology companies to maintain the integrity and security of digital platforms.
Latest from Softonic
- 1 in 3 Android apps have serious API leakage issues, according to a recent study
- The showrunner of the Splinter Hell series wants to be clear "it's important to pull the thorn from the source material"
- Dungeons & Dragons is filled with monsters for its fiftieth anniversary
- Tencent says that if their new game is a plagiarism of Horizon Zero Dawn, Sony should take a look at what they have done with Breath of the Wild and Far Cry
You may also like
- News
1 in 3 Android apps have serious API leakage issues, according to a recent study
Read more
- News
The rise of fake captchas: a new weapon for cybercriminals
Read more
- News
Google disables the 100 results per page feature and leaves users stunned
Read more
- News
The second season hasn't even premiered yet, and Disney+ has already renewed this superhero series for a third one
Read more
- News
Is Hollow Knight: Silksong too difficult? Its creators defend that it is not
Read more
- News
Microsoft teams up with ASUS to launch ROG Xbox Ally and compete with Steam Deck
Read more