SBIE2328
Message SBIE2328 Failed to resolve chrome sandbox hook %2
Severity: Error (popup)
Note
The current hook installer logs SBIE2328 when browser-hook resolution fails. It also records "Chrome Hook Unresolved" in the hook monitor output for calls through SbieDll_Hook; enabling API/hook tracing is not required for this failure record.2
Description
This message indicates that Sandboxie's DLL hook code attempted to follow a recognised browser (Chromium/Chrome-derived or Firefox) runtime hook but could not resolve a usable target address. The message includes the function name and an error code, for example NtMapViewOfSection (1).12
Sandboxie contains heuristic logic that recognises the way some browsers install an in-process hook (a small trampoline that jumps to an interceptor). When the pattern is recognised, Sandboxie tries to locate the saved original target function and hook it instead of the small trampoline. If resolution fails or the returned address fails validation, SBIE2328 is logged.12
Error Codes
| Code | Meaning |
|---|---|
1 |
Hook_CheckChromeHook returned its failure sentinel, (void*)-1: a recognised browser-hook path did not yield a usable saved original target. This does not mean that the named API export is missing. |
2 |
The scanner returned an address, but Hook_IsCodeAddress rejected it. VirtualQuery failed, or the address was not in committed executable memory, or its protection included PAGE_GUARD or PAGE_NOACCESS. |
The x64 and ARM64 scanners already validate their scan regions, pointer slots and resolved targets. A candidate rejected inside those scanners can therefore result in code 1; code 2 is the separate final check in the DLL hook installer. The code alone does not identify the exact instruction or pointer that failed.12
If no supported outer trampoline pattern is recognised, the helper returns NULL and this path does not log SBIE2328. On either error code, Sandboxie retains the original source address and continues attempting to install its hook there. The message does not by itself mean that the subsequent hook installation failed.12
Typical Causes
- The browser or target module changed its internal code layout, so the scanner no longer finds the expected saved-original instruction pattern.1
- A scan region or pointer slot fails memory validation, the saved pointer is null, or a candidate target is not executable.12
- A recognised trampoline leads to an interceptor layout that the architecture-specific scanner does not support.3
Suggested Actions
- Update Sandboxie to the latest release. Hook heuristics are occasionally updated to match browser changes.3
- If the issue occurs only for a specific browser version or vendor, compare with another browser build. Disabling API/hook tracing does not disable this resolution path or fix the failure.2
- Collect the complete message, including the function name and error code, plus the Sandboxie version, browser version, process image, architecture and module name. Include the hook monitor output when reporting the issue to Sandboxie maintainers.
- Do not treat
FuncSkipHookorSkipHookas a general fix.FuncSkipHookbypasses the hook entirely for matching function names inSbieDll_Hook, not just browser-target resolution;SkipHookis honoured only by callers that checkDll_SkipHook. Skipping hooks changes Sandboxie's interception behaviour and should be used only for a targeted diagnostic recommended by maintainers.2
Related Messages and Settings
- SBIE2303 - Generic hook error used for a variety of hook failures.
- SBIE2329 - Failed to find a Fast-Forward Sequence (FFS) target on the ARM64EC hook path.
- FuncSkipHook - Function-name setting consulted before hook installation by
SbieDll_Hook. - SkipHook - Process-specific list of hook identifiers consulted by callers of
Dll_SkipHook; it is not a universal module-level bypass.
Implementation Notes and Footnotes
Technical details below are intended for maintainers and advanced users who want to trace how the message can be generated. Exact line numbers are intentionally omitted.
-
The hook-resolution logic is implemented in
Sandboxie/common/hook_util.c, inHook_CheckChromeHook(...)and its architecture-specific scanners. A recognised browser-hook path whose scanner cannot resolve a target returns(void*)-1; no matching outer pattern returnsNULL. The x64 and ARM64 scanners use memory-query helpers to bound instruction reads, validate pointer slots and accept executable targets. The x64 Firefox path uses the exportedg_originalsrange and can follow one validated image-local stub pointer. ↩↩↩↩↩↩ -
In
Sandboxie/core/dll/dllhook.c,SbieDll_HookFunc(...)callsHook_CheckChromeHook(...), assigns code1for(void*)-1, or code2whenHook_IsCodeAddress(...)rejects a returned address. On either error it callsSbieApi_Log(2328, _fmt1, SourceFuncName, ChromeError), where_fmt1is%s (%d), and setsHOOK_STAT_CHROME_FAILwhen statistics are supplied. It retainsSourceFuncand proceeds to the architecture-specific hook installer.SbieDll_Hook(...)emits "Chrome Hook Unresolved" throughSbieApi_MonitorPutMsg(...)for this failure flag even withoutDll_HookTrace. The same file implementsSbieDll_FuncSkipHook(...)andDll_SkipHook(...). ↩↩↩↩↩↩↩↩ -
The heuristics cover supported Chromium/Firefox hook layouts on x86, x64 and ARM64, rather than every possible browser trampoline. Browser layout changes can require scanner updates. The current x64 code includes Chrome's R15 saved-original load and a bounded Firefox one-hop resolver. ↩↩