Skip to content

SBIE2328

Message SBIE2328 Failed to resolve chrome sandbox hook %2

Severity: Error (popup)

Note

The current hook installer logs SBIE2328 when browser-hook resolution fails. It also records "Chrome Hook Unresolved" in the hook monitor output for calls through SbieDll_Hook; enabling API/hook tracing is not required for this failure record.2

Description

This message indicates that Sandboxie's DLL hook code attempted to follow a recognised browser (Chromium/Chrome-derived or Firefox) runtime hook but could not resolve a usable target address. The message includes the function name and an error code, for example NtMapViewOfSection (1).12

Sandboxie contains heuristic logic that recognises the way some browsers install an in-process hook (a small trampoline that jumps to an interceptor). When the pattern is recognised, Sandboxie tries to locate the saved original target function and hook it instead of the small trampoline. If resolution fails or the returned address fails validation, SBIE2328 is logged.12

Error Codes

Code Meaning
1 Hook_CheckChromeHook returned its failure sentinel, (void*)-1: a recognised browser-hook path did not yield a usable saved original target. This does not mean that the named API export is missing.
2 The scanner returned an address, but Hook_IsCodeAddress rejected it. VirtualQuery failed, or the address was not in committed executable memory, or its protection included PAGE_GUARD or PAGE_NOACCESS.

The x64 and ARM64 scanners already validate their scan regions, pointer slots and resolved targets. A candidate rejected inside those scanners can therefore result in code 1; code 2 is the separate final check in the DLL hook installer. The code alone does not identify the exact instruction or pointer that failed.12

If no supported outer trampoline pattern is recognised, the helper returns NULL and this path does not log SBIE2328. On either error code, Sandboxie retains the original source address and continues attempting to install its hook there. The message does not by itself mean that the subsequent hook installation failed.12

Typical Causes

  • The browser or target module changed its internal code layout, so the scanner no longer finds the expected saved-original instruction pattern.1
  • A scan region or pointer slot fails memory validation, the saved pointer is null, or a candidate target is not executable.12
  • A recognised trampoline leads to an interceptor layout that the architecture-specific scanner does not support.3

Suggested Actions

  1. Update Sandboxie to the latest release. Hook heuristics are occasionally updated to match browser changes.3
  2. If the issue occurs only for a specific browser version or vendor, compare with another browser build. Disabling API/hook tracing does not disable this resolution path or fix the failure.2
  3. Collect the complete message, including the function name and error code, plus the Sandboxie version, browser version, process image, architecture and module name. Include the hook monitor output when reporting the issue to Sandboxie maintainers.
  4. Do not treat FuncSkipHook or SkipHook as a general fix. FuncSkipHook bypasses the hook entirely for matching function names in SbieDll_Hook, not just browser-target resolution; SkipHook is honoured only by callers that check Dll_SkipHook. Skipping hooks changes Sandboxie's interception behaviour and should be used only for a targeted diagnostic recommended by maintainers.2
  • SBIE2303 - Generic hook error used for a variety of hook failures.
  • SBIE2329 - Failed to find a Fast-Forward Sequence (FFS) target on the ARM64EC hook path.
  • FuncSkipHook - Function-name setting consulted before hook installation by SbieDll_Hook.
  • SkipHook - Process-specific list of hook identifiers consulted by callers of Dll_SkipHook; it is not a universal module-level bypass.

Implementation Notes and Footnotes

Technical details below are intended for maintainers and advanced users who want to trace how the message can be generated. Exact line numbers are intentionally omitted.


  1. The hook-resolution logic is implemented in Sandboxie/common/hook_util.c, in Hook_CheckChromeHook(...) and its architecture-specific scanners. A recognised browser-hook path whose scanner cannot resolve a target returns (void*)-1; no matching outer pattern returns NULL. The x64 and ARM64 scanners use memory-query helpers to bound instruction reads, validate pointer slots and accept executable targets. The x64 Firefox path uses the exported g_originals range and can follow one validated image-local stub pointer. ↩↩↩↩↩↩

  2. In Sandboxie/core/dll/dllhook.c, SbieDll_HookFunc(...) calls Hook_CheckChromeHook(...), assigns code 1 for (void*)-1, or code 2 when Hook_IsCodeAddress(...) rejects a returned address. On either error it calls SbieApi_Log(2328, _fmt1, SourceFuncName, ChromeError), where _fmt1 is %s (%d), and sets HOOK_STAT_CHROME_FAIL when statistics are supplied. It retains SourceFunc and proceeds to the architecture-specific hook installer. SbieDll_Hook(...) emits "Chrome Hook Unresolved" through SbieApi_MonitorPutMsg(...) for this failure flag even without Dll_HookTrace. The same file implements SbieDll_FuncSkipHook(...) and Dll_SkipHook(...). ↩↩↩↩↩↩↩↩

  3. The heuristics cover supported Chromium/Firefox hook layouts on x86, x64 and ARM64, rather than every possible browser trampoline. Browser layout changes can require scanner updates. The current x64 code includes Chrome's R15 saved-original load and a bounded Firefox one-hop resolver. ↩↩