Zero Day Engineering Supplies • Private Intelligence: @zerodayalpha • Community: discord.com/invite/hvKy6rsPR…

Joined June 2021
Photos and videos
Welcome to Zero Day Engineering Links Topics: • vulnerability research • reverse engineering • system internals • exploit engineering We select, feature and comment mature, original, top quality community research and code which has a clear impact and practical applications
1
11
65
Analysis of VMware vCenter heap overflow vulnerability exploited at Matrix Cup competitions in China, June 2024 (CVE-2024-38812): blog.sonicwall.com/en-us/202… Another one in same code, 2023: blog.sonicwall.com/en-us/202… ** Both are RCE to management console, not a hypervisor VM escape!

22
87
9,628
[Browser Exploitation] Insightful little analysis of v8 CVE-2024-7965: bi.zone/eng/expertise/blog/a… PoC: github.com/bi-zone/CVE-2024-… Logic bug in Turbofan's "sea of nodes" IR implementation allows for OOB array access! Exploit in-the-wild reported by Google & CISA on 26th August 2024
1
32
110
30,151
Interestingly, the elevation of privilege part of the chain is still not known Tracker issue🔒 issues.chromium.org/issues/3…

788
Zero Day Engineering | Community & Industry retweeted
Slides: "Fuzzing from First Principles": zerodayengineering.com/resea… I heard that the podcast reached all-time-highest number of viewers, thank you for coming to see me!
6
46
244
16,156
Zero Day Engineering | Community & Industry retweeted
6 Sep 2024
(CVE-2024-3914)[330759272][Pwn2Own 2024][DOMArrayBuffer]DOMArrayBuffer confused about ownership of backing buffer -> UAF is now open with PoC and exploit issues.chromium.org/issues/3… PoC: issues.chromium.org/action/i… Exploit: issues.chromium.org/action/i… WP: issues.chromium.org/action/i… @0x10n

30 Apr 2024
(CVE-2024-3914)[330759272][DOMArrayBuffer]UAF in v8. "Removing this newly introduced CHECK to be able to merge fixes in this area - we still violate this invariant but the fixes are a step into the right direction."😅 chromium-review.googlesource… chromium-review.googlesource… @0x10n
14
55
10,471
Short and to the point, patch analysis PoC of Windows Kernel ntoskrnl LPE bug (CVE-2024-38106), by @b1thvn_: pixiepointsecurity.com/blog/… This bug is being exploited in-the-wild, as part of a browser exploit chain with Chrome v8 RCE (CVE-2024-7971), reported in August 2024
13
47
4,876
Zero Day Engineering | Community & Industry retweeted
0-Day Insights - Deep Dive: Qualcomm MSM Linux Kernel & ARM Mali GPU 0-day Exploit Attacks of October 2023 zerodayengineering.com/insig… (by @alisaesage)

2
31
121
35,628
Tracking bug for v8 the_hole bug class mitigations bugs.chromium.org/p/chromium…

1
6
19
6,231
Zero Day Engineering | Community & Industry retweeted
Research insights on recent Chrome 0day in Skia (CVE-2023-6435) from our lab: 1. The bug is an integer overflow in Skia, an open source library for rendering 2D graphics which which is used in Chromium backend. 2. The bug can be used to escape browser sandbox in Chrome app on Android. 3. At least one more bug -in one of the renderer subsystems, such as v8- is required to complete the attack with a full chain exploit. Google did not disclose the other bug at this time. 4. The bug cannot be used to achieve a full sandbox escape on common desktop deployments of Google Chrome. 5. Based on the above, we hypothesize that the original 0day attack vector and the exploit chain was targeting Android devices specifically. 6. The bug seems to be available and reachable in broad-scope Chromium (including common desktop deployments of Chrome browser), but an additional 3rd vulnerability would be required to execute arbitrary code with the same level of privilege as in the original 0day attack in most popular deployment configurations. Therefore, overal impact of the bug is somewhat scoped. 7. The bug will strongly affect Chrome embedders which use unsandboxed GPU process. We did not look further into this, but Chrome-based systems such as electron framework and derivatives should be patched quickly. 8. The bug is not explicitly related to the previous 0day in Skia (CVE-2023-2136). I.e. it's not a patch bypass of the latter, and not located in the same subsystem of code. 9. Both bugs (6435 and 2136) are focused on bypassing in-code checks, which implicitly suggests the same specialized bughunting workflow, and therefore, possibly the same attacker. 10. The bug is not very trivial to reproduce. Strong familiarity with GPU-level graphics internals is required. Chrome release notes: chromereleases.googleblog.co… Patchset: skia.googlesource.com/skia.g… Issue tracker (restricted): crbug.com/1505053 Analysis by @alisaesage
6
56
254
56,545
Chromium [WIP] internal fuzzing map by source code directory, official dashboard analysis.chromium.org/covera…

10
42
17,895
Excellent high-level exposure of chromium mojo system internals, apparently the author is one of the chromium internal team (links to google-private docs included)
3
719
List of Chromium security bugs (with technical details) that received top bounty rewards from Google VRP: bugs.chromium.org/p/chromium… Congrats to bug finders!

4
18
7,318