
xvonfers
@xvonfers
Browser & *nix VR.
Ex SIGINT
ID: 1695083774881550336
25-08-2023 14:41:18
5,5K Tweet
3,3K Followers
823 Following


Here are the slides for my keynote, 'Mobile Exploitation, the past, present, and the future' at #Zer0Con2023. Zer0con was a blast as always, thank you POC_Crew 👨👩👦👦!! 🚀💫 github.com/externalist/pr…


[361862752]Compiled JS-to-WASM wrappers don't guard against `trusted_function_data` overwrites(v8sbx escape) issues.chromium.org/issues/3618627… PoC: issues.chromium.org/action/issues/… PoC(changed the SFI pointer offset from 0x14 to 0x10) issues.chromium.org/action/issues/… Reported by Matthias Pleschinger
![xvonfers (@xvonfers) on Twitter photo [361862752]Compiled JS-to-WASM wrappers don't guard against `trusted_function_data` overwrites(v8sbx escape)
issues.chromium.org/issues/3618627…
PoC:
issues.chromium.org/action/issues/…
PoC(changed the SFI pointer offset from 0x14 to 0x10)
issues.chromium.org/action/issues/…
Reported by Matthias Pleschinger [361862752]Compiled JS-to-WASM wrappers don't guard against `trusted_function_data` overwrites(v8sbx escape)
issues.chromium.org/issues/3618627…
PoC:
issues.chromium.org/action/issues/…
PoC(changed the SFI pointer offset from 0x14 to 0x10)
issues.chromium.org/action/issues/…
Reported by Matthias Pleschinger](https://pbs.twimg.com/media/Gi-OlCDXwAAa4ss.png)












