This research allowed me to find critical bugs in several electron applications by finding public n-day exploits for older versions of chrome and adapting them to the electron framework.
https://t.co/kZKmvuABkq
#BugBounty
To wrap up 2022, I'm releasing the final part of my 3-part browser exploitation series on Chrome!
In this post, we demonstrate the practical use of the concepts we've learned throughout the series by analyzing and exploiting CVE-2018-17463.
Enjoy!
https://t.co/Xhrnh4fqNB
In a new guest blog, #Pwn2Own winner @_manfp details CVE-2024-2887 - a bug he used to exploit both #Chrome and #Edge during the contest on his way to winning Master of Pwn. He breaks down the root cause and shows how he exploited it. Read the details at https://t.co/BgMGfczO8U
We wrote about a Chrome bug that arose due to the manner in which V8's Maglev tried to optimize the number of allocations it made. Now, in the newer releases with Trusted Pointers, the v8 heap sandbox looking a bit more formidable 👀
The recording of our (me, @bzvr_, @kucher1n) #37c3 talk “Operation Triangulation: What You Get When Attack iPhones of Researchers” was published! https://t.co/j97J9TiXsC
@hardik05 It really depends on many factors such as product’s security maturity and how good and stable your harness is how deep you are hooking into the program for execution speed. In generic terms yea it will take some time.
🧨 TOOL ANNOUNCEMENT 🧨
We are glad to release a VSCode extension to help out during code reviews!
Create inline notes 📝, import findings from Semgrep 🛠️, collaborate with others in real-time 🤝, and more!
Find out more at:
https://t.co/AswhyyjH4M
#infosec#appsec#pentest