[2]After our failed competition, we headed to Apple Store and bought the mbp m5 and spent less than half an hour to set it up and found a fixed offset is changed 1 bit on it, so we just change 1 bit on our exp and it worked with a 100% success rate. Yes just 1 bit change, 1 to 2.
In another video highlight from day two of #Pwn2Own Berlin, Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois) from Palo Alto Networks successfully target Mozilla Firefox. https://t.co/z1jceHDNNq
Congrats to @mozilla for being the first vendor to patch their #Pwn2Own bugs. Oh - and go update #Firefox to get the fixes. That's two years in a row Mozilla has been the fastest. Well done!
First blood: Mozilla Firefox pwned at first attempt (in less than 2 seconds) using an out-of-bounds write vulnerability by Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois) from Palo Alto Networks.
Really thrilled and truly honored to receive this year's Pwnie Award for Most Innovative Research with @le_douds. It's a wonderful wrap-up for our work. Can't wait to start the next journey of our research. Great thanks to @PwnieAwards! #defcon32
We finished our presentation at #BHUSA and the slides were published here: https://t.co/zMPwN1nsFS, you can also find the latest slides and demo here: https://t.co/cuJkmP0b28, enjoy, especially for our new "field confusion" V8 sbx escape technique : ) @le_douds@BlackHatEvents
#BHUSA We are glad our talk "Let the Cache Cache and Let the WebAssembly Assemble: Knockin’ on Chrome’s Shell" was accepted for Black Hat USA 2024, we'll disclose our #Chrome research demonstrated at #Pwn2Own 2024. Stay tuned : ) https://t.co/FRGfyC44gR @le_douds@BlackHatEvents
Confirmed! @le_douds and @Ga1ois from Palo Alto used an OOB Read plus a novel technique for defeating V8 hardening to get arbitrary code execution in the renderer. The were aboe to exploit #Chrome and #Edge with the same bugs, earning $42,500 and 9 Master of Pwn points. #Pwn2Own