tail -f internet | grep exploit

Joined June 2010
Photos and videos
clem1 retweeted
We analyzed the Coruna exploit kit and found intriguing code overlaps with Operation Triangulation. Full analysis on our blog: link below.
4
88
428
38,563
clem1 retweeted
BREAKING: powerful iPhone hacking tools used by Chinese criminals originated from US defense giant L3 Harris. The $LHX zero-click exploits went to Russian spies too. Unbelievable harm to our collective security. Scoop by @lorenzofb, here's why this matters 1/
31
857
2,378
270,061
A full iOS exploit toolkit, "Coruna," has been found in the wild, hacking iPhones that visited infected websites, used by Russian spies targeting Ukrainians and thieves targeting Chinese crypto holders. And it may have been created for the US government. wired.com/story/coruna-iphon…
8
298
709
100,946
Coruna exploit kit is targeting iOS. Coruna leverages 23 exploits against Apple devices running iOS 13-17.2.1. It is being used for espionage, and by financially motivated actors to steal crypto. Update your iOS devices, and learn more about this threat: bit.ly/4rbeltc
7
117
353
119,670
clem1 retweeted
New Project Zero blogpost series describing a 0-click exploit chain targeting Pixel 9, featuring a Dolby decoder bug spotted by yours truly.
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/p…
1
14
149
14,730
clem1 retweeted
We launched a redesigned Project Zero website today at projectzero.google ! To mark the occasion, we released some older posts that never quite made it out of drafts. Enjoy!
7
62
366
46,354
clem1 retweeted
Adobe DNG SDK: areaSpec overlap miscalculation lead to integer overflow, leading to OOB read/write project-zero.issues.chromium…

12
44
7,397
clem1 retweeted
This issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group. CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. support.apple.com/en-us/1258… [N/A][466192044] High CVE-2025-14174: Out of bounds memory access in ANGLE. Reported by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group on 2025-12-05 chromereleases.googleblog.co… ANGLE and WebGL 2.0 in WebKit trac.webkit.org/wiki/Anglefo…
1
16
114
28,713
clem1 retweeted
An analysis of a recent 0-click exploit targeting Samsung devices: googleprojectzero.blogspot.c…

4
146
446
65,988
clem1 retweeted
🚨 A huge leak exposes the new targets and internal operations of Intellexa, the secretive and murky company behind the notorious Predator spyware. Introducing #IntellexaLeaks, a joint investigation with partners @insidestory_gr, @haaretzcom & WAV Research Collective 🧵👇
2
44
111
21,730
clem1 retweeted
3 Dec 2025
We derestricted a number of vulnerabilities found by Big Sleep in JavaScriptCore today: issuetracker.google.com/issu… All of them were fixed in the iOS 26.1 (and equivalent) update last month. Definitely some cool bugs in there!

2
33
176
18,328
clem1 retweeted
All my recent activity wasn't for nothing...I'm pleased to announce that I'll be speaking at @DistrictCon with @natashenka about a 0-click to kernel exploit chain for the Pixel 9 in January!
3
17
206
15,789
clem1 retweeted
Samsung: QuramDng getOverlap miscalculation leads to integer overflow, leading to out-of-bounds read/write project-zero.issues.chromium…

10
43
8,486
clem1 retweeted
18 Sep 2025
woah...Exploited ITW (CVE-2025-10585)[445380761][compiler][maglev]Type Confusion chromium-review.googlesource… chromium-review.googlesource… chromereleases.googleblog.co… Reported by Google TAG
1
15
50
8,490
clem1 retweeted
2 Sep 2025
We’re thrilled to announce Donncha Ó Cearbhaill (@DonnchaC) as our keynote speaker for HEXACON 2025! 💥 No doubt he has plenty of juicy stories up his sleeve 👾
8
36
7,467
clem1 retweeted
If you've been keeping track on the Big Sleep bug tracker at goo.gle/bigsleep you might have noticed it lists more bugs now compared to last week. Including a "High impact issue in V8" :)

3
20
101
23,161
clem1 retweeted
15 Jul 2025
Exploited ITW (CVE-2025-6558)[427162086]Incorrect validation of untrusted input(transform feedback buffer modification) chromium-review.googlesource… chromereleases.googleblog.co… Reported by Clément Lecigne(@_clem1) and Vlad Stolyarov(@vladhiewsha)
2
23
67
29,265
clem1 retweeted
1 Jul 2025
Leak hole PoC for Chrome in-the-wild vulnerability CVE-2025-6554 published yesterday: github.com/DarkNavySecurity/…
5
54
178
32,651
clem1 retweeted
After 6 months of responsible disclosure, proud to announce our team discovered 13 (mostly exploitable) vulnerabilities in Samsung Exynos processors! Kudos to @st424204, @n0psledbyte, @Peterpan980927 & @rainbowpigeon_ CVE-2025-23095 to CVE-2025-23107 📍 semiconductor.samsung.com/su…

2
22
159
22,813