Mmm
577 posts


@hackyzh They also missed my bisect bonus and report quality bonus. I think its bc I accidentally made several of the comments protected (it auto did and I didn't know i could change at first). So gonna ask them to look at it again.
English

@hackyzh Yes I can. I provided poc with proven RIP control. Pc control. Was full write any value i want any location any size.
English

git.codelinaro.org/clo/la/platfor… I saw this patch a few months ago, but I haven't been able to create a reproducible proof-of-concept (PoC).

English
Mmm retweetet

We are hiring! CPU security stuff google.com/about/careers/…
English
Mmm retweetet

[446722008][reward: $100000] heap-use-after-free in content::indexed_db::Database::connections_ when force_closing_ is true
crbug.com/446722008
English

@hackyzh They are really awful regarding bounties i found bug in microsoft.com main site and they refused to pay me bounty.
English

@hackyzh Hmm ok I took a quick look at the code, there are some changes, but nothing that should affect the PoC, so I think I can definitely get it working in QEMU on that same kernel version.
But yeah I don't have a real device to test against so I'll finish the exploit in QEMU later 🥲
English

In my previous post about CVE-2025-38352, I used a kernel patch to extend the race window to help trigger the vulnerability.
I've since improved it to work without the kernel patch. @hackyzh 👀
I also wrote a "Part 2" of the blog post. It's linked at the end of this thread!

Faith 🇧🇩🇦🇺@farazsth98
After reading @streypaws blog post on CVE-2025-38352, I ended up writing my own PoC for it. I also wrote a blog post on my approach to analyzing and recreating the PoC. Hopefully it is useful to others! See link in the reply tweet below!
English

@farazsth98 Linux localhost 5.10.157-android13-4-00001-g5c7ff5dc7aac-ab10381520
English

@hackyzh Oh, hmm.. I don't have any devices to test with 🥲 Do you have any idea what the issue could be? I wonder if the race window is not long enough because it can't create enough threads or if it's something else
English





