Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile
Ivan Fratric ๐Ÿ’™๐Ÿ’›

@ifsecure

Security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own.
Backup @[email protected]

ID: 351702234

linkhttp://ifsec.blogspot.com/ calendar_today09-08-2011 16:37:46

1,1K Tweet

17,17K Takipรงi

196 Takip Edilen

Ivan Krstiฤ‡ (@radian) 's Twitter Profile Photo

๐Ÿ”บiPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-inโ€ฆ

Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile Photo

If you're keeping an eye on the Big Sleep issue tracker (goo.gle/bigsleep) you might have noticed that the detailed reports for some bugs (e.g. issuetracker.google.com/issues/4351567โ€ฆ) are now public. Note however that all reports are lovingly crafted by a human and not AI-generated.

Seth Jenkins (@__sethjenkins) 's Twitter Profile Photo

I've derestricted 3 unfixed issues in the Google BigWave driver - these bugs are reachable from media decoding contexts on Pixel devices. E.g. project-zero.issues.chromium.org/issues/4265679โ€ฆ

Seth Jenkins (@__sethjenkins) 's Twitter Profile Photo

Oh also this, which is technically WAI but has the unfortunate side effect (because of linear map non-randomization) that instead of bypassing KASLR, you can just use 0xffffff8000010000 as your kernel base instead.... project-zero.issues.chromium.org/issues/4342697โ€ฆ

Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile Photo

In isolation, project-zero.issues.chromium.org/issues/4342697โ€ฆ and project-zero.issues.chromium.org/issues/4342084โ€ฆ might not appear very critical. However, together they mean KASLR on Pixel is broken :(. Both of these issues have been declared "working as intended" by the respective vendors :(

Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile Photo

A new Project Zero blogpost by Jann Horn - [email protected] in which he writes about an interesting and little-known bug class that affected web browses, Linux and, most recently, macOS. The bug class can also be used for leaking pointer tag information in some scenarios.

RyotaK (@ryotkak) 's Twitter Profile Photo

I reported an arbitrary code execution in Unity Runtime, which affects all versions starting from Unity 2017.1. As the vulnerability can be exploited without specific usage, I strongly encourage developers to patch. Technical details below: flatt.tech/research/postsโ€ฆ

Oliver Chang (@halbecaf) 's Twitter Profile Photo

Really excited to finally announce CodeMender! As part of this we've already submitted and upstreamed several patches to OSS projects via OSS-Fuzz. Check out our post at: deepmind.google/discover/blog/โ€ฆ There will be more technical details and exciting announcements to come!

Natalie Silvanovich (@natashenka) 's Twitter Profile Photo

Serious bugs often occur in third-party components integrated by other software. Ivan Fratric ๐Ÿ’™๐Ÿ’› and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click. project-zero.issues.chromium.org/issues/4280754โ€ฆ

Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile Photo

A fun fact about this bug is that we only had an (entirely internally imposed) ~ 8 hour deadline to find it. Looking forward to sharing more info about it.

Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile Photo

โ€œI have [...] extreme fear because once things hit this level, you never know whatโ€™s going to happenโ€. Well I guess now he knows how his victims feel.

Samuel GroรŸ (@5aelo) 's Twitter Profile Photo

We derestricted crbug.com/382005099 today which might just be my favorite bug of the last few years: bad interaction between WebAudio changing the CPU's handling of floats and V8 not expecting that. See crbug.com/382005099#commโ€ฆ for a PoC exploit. Also affected other browsers

Seth Jenkins (@__sethjenkins) 's Twitter Profile Photo

We really should be talking about this more....KASLR is just not working properly on Android right now, and it hasn't for a long time. googleprojectzero.blogspot.com/2025/11/defeatโ€ฆ

Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile Photo

Great news for browser security (and not just because it cites my XSLT research :)). A lot of younger folks don't even know this feature exists, yet is/was the default attack surface in all major web browsers with a history of exploitation. developer.chrome.com/docs/web-platfโ€ฆ