Ivan Fratric ๐๐
@ifsecure
Security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own.
Backup @[email protected]
ID: 351702234
http://ifsec.blogspot.com/ 09-08-2011 16:37:46
1,1K Tweet
17,17K Takipรงi
196 Takip Edilen
๐บiPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-inโฆ
If you're keeping an eye on the Big Sleep issue tracker (goo.gle/bigsleep) you might have noticed that the detailed reports for some bugs (e.g. issuetracker.google.com/issues/4351567โฆ) are now public. Note however that all reports are lovingly crafted by a human and not AI-generated.
In isolation, project-zero.issues.chromium.org/issues/4342697โฆ and project-zero.issues.chromium.org/issues/4342084โฆ might not appear very critical. However, together they mean KASLR on Pixel is broken :(. Both of these issues have been declared "working as intended" by the respective vendors :(
Super cool potential ASLR leak via dictionary hashing by Jann Horn - [email protected]! googleprojectzero.blogspot.com/2025/09/pointeโฆ
A new Project Zero blogpost by Jann Horn - [email protected] in which he writes about an interesting and little-known bug class that affected web browses, Linux and, most recently, macOS. The bug class can also be used for leaking pointer tag information in some scenarios.
Serious bugs often occur in third-party components integrated by other software. Ivan Fratric ๐๐ and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click. project-zero.issues.chromium.org/issues/4280754โฆ