Missed out on Pwn2Own2026 Berlin because it was way too crowded this time. 🥲
Well, here’s the Ollama RCE that I was going to bring.
Still unpatched and working (v0.22.1 in the video, but still working)
Update on CVE-2025-66478 (React2Shell):
An npm package has been released to scan and update affected Next.js apps. Use `npx fix-react2shell-next` to update to patched versions.
All users should update as soon as possible.
More details our blog:
https://t.co/fjNfpv3huI
CVE-2025-10200)[$43000][Critical][Serviceworker][440454442]UAF in ServiceWorkerVersion::FinishRequestWithFetchCount() in browser process(1-click RCE in browser process (outside sandbox)) is now open with PoC
https://t.co/bMhOAsecwR
Reported by Looben Yang