X41 D-Sec GmbH releases Browser Security White Paper, assessing Google Chrome, Microsoft Edge and Internet Explorer
Aachen, 19 September 2017. X41 D-Sec GmbH (“X41”) – a research driven IT-Security company – released an in-depth analysis of the three leading enterprise web browsers Google Chrome, Microsoft Edge, and Internet Explorer. The senior security experts of X41 have the necessary experience and track record to analyze complex applications such as modern web browsers.
X41 analyzed the design, attack surface, and resilience of the browsers against possible attacks. In conclusion Google Chrome was found to be the most resilient against attacks due to a tighter lock down of components and more secure design decisions.
The full paper can be downloaded at: https://browser-security.x41-dsec.de/X41-Browser-Security-White-Paper.pdf
Markus Vervier, Managing Director of X41 comments: “Modern web browsers such as Chrome or Edge improved security in recent years. Exploitation of vulnerabilities is certainly more complex today and requires a higher skill than in the past. However, the attack surface of modern web browsers is increasing due to new technologies and the increasing complexity of web browsers themselves.”
“Browsers are among the most hardened applications. Most other software products do not perform security tests and deploy this many mitigations to make abuse harder” comments Eric Sesterhenn of X41, who helps companies to secure their applications and infrastructure.
Since all non-trivial software have bugs and security vulnerabilities, X41 believes security barriers that prevent hackers of taking advantage of these vulnerabilities are most important. X41 assessed these barriers with the following results:
- Chrome is the most resilient against attacks due to a tight lockdown of components, separation of duties, and greater identifiable vendor efforts for automated vulnerability discovery.
- The security level of Internet Explorer is decreased due to a weakened sandbox (Protected Mode).
- Microsoft Edge is more hardened against exploitation than Internet Explorer due to the stronger sandboxing and the absence of dangerous legacy technologies.
- Chrome supports more modern web technologies that might increase attack surface such as WebAssembly and HTML5 features.
- Reaching dangerous legacy functionality from Microsoft Edge is easier than in Chrome. For example a fallback to Internet Explorer is suggested by the Edge UI on certain websites by default.
X41 conducted its analysis and conclusions against a background of contractual independence, having no conflict of interests. However, the time resources required for X41 to conduct this comprehensive research were sponsored by Google.
ABOUT X41 D-Sec GmbH
ACXIT’s IT-Security partner & affiliated investment X41 D-Sec GmbH is a renowned expert provider for dedicated high quality security research, application security services, penetration tests, and full red teaming. Having extensive industry experience and expertise in the field of IT security, a highly effective security team of world class security experts enables X41 to perform premium security services.
Fields of expertise in the area of application security are code reviews, binary reverse engineering, and vulnerability discovery. Custom research and high quality IT security services are core competencies of X41. (www.x41-dsec.de)
ABOUT ACXIT Capital Partners
ACXIT is a leading international corporate finance and investment advisory firm for mid-market clients and entrepreneurs in Europe and beyond. Since 1998, ACXIT offers its clients comprehensive corporate finance advisory services including M&A and capital markets advisory as well as restructuring, equity/debt and strategic advisory. As an independent, privately owned firm we maintain offices in Frankfurt, Berlin, Munich, Leipzig, Zurich and Hong Kong as well as strong alliances in France, China, India and the USA. (www.acxit.com)
X41 D-Sec GmbH
ACXIT Capital Holding GmbH
Bockenheimer Landstraße 24
60323 Frankfurt am Main
Dr. Ingmar Ackermann, Managing Partner