ggwhyp

11 posts

ggwhyp banner
ggwhyp

ggwhyp

@ggwhyp

Katılım Ağustos 2025
148 Takip Edilen829 Takipçiler
ggwhyp
ggwhyp@ggwhyp·
I want to clarify my disclosure. After I couldn’t participate in Pwn2Own due to capacity limits, I reported my findings through the vendor’s official process, as I believed it was the best course of action available to me. This was not revenge or an attempt to disrupt anyone.
English
4
3
71
6.6K
ggwhyp
ggwhyp@ggwhyp·
@TheDog0402 The RCE was found via manual audit, while the sandbox escape was found using an LLM. The LLM alone couldn’t find the RCE (though it may be due to my limited skill), but with LLM-assisted analysis, it likely would’ve been found ~10× faster.
English
0
1
48
2.9K
TheDog
TheDog@TheDog0402·
@ggwhyp wow, it’s impressive. i am curious about how you found those bugs, fuzz? AI? Or human brain ?
English
1
0
5
3.2K
ggwhyp
ggwhyp@ggwhyp·
I was hoping to compete in Pwn2Own with a Firefox full-chain entry, but unfortunately it was rejected. I’ve reported the vulnerability to the Mozilla team.
English
31
95
712
102.5K
ggwhyp
ggwhyp@ggwhyp·
@CarriKleib79705 @LunacySoft I used GPT 5.5 xhigh. There can be some gaps in vulnerability analysis, but root cause analysis generally works reliably.
English
0
0
3
597
ggwhyp
ggwhyp@ggwhyp·
@MikeyFromUK No, the vulnerability can be exploited remotely without any user interaction required.
English
4
0
20
2.8K
Mike
Mike@MikeyFromUK·
@ggwhyp Does the exploit only work in local host?
English
1
0
0
2.9K
ggwhyp
ggwhyp@ggwhyp·
@LunacySoft Of course. In the case of the RCE bug, it was found through manual auditing. Interestingly, even when I tried to guide an LLM to find the bug, it still struggled to identify it reliably. I’m also considering writing about this aspect as well.
English
1
0
26
2.3K
LunacySoft
LunacySoft@LunacySoft·
@ggwhyp Wil we get a write up once it’s patched?
English
1
0
1
2.5K
ggwhyp
ggwhyp@ggwhyp·
@Reelix My registration was rejected because the event had already reached full capacity.
English
3
0
59
4.1K
Reelix
Reelix@Reelix·
@ggwhyp Rejected? Why? User interaction required?
English
2
0
9
4.4K
ggwhyp
ggwhyp@ggwhyp·
@MiniMjStar I plan to publish a technical analysis report after the release build has been patched and an appropriate amount of time has passed to ensure safe public disclosure.
English
2
0
26
3K
ggwhyp
ggwhyp@ggwhyp·
6fbfb61d808e6084e9fe14993e6c1c86d27dd1c53c54bad0a1e33c0d20e2204e
Italiano
0
0
5
3.8K
ggwhyp
ggwhyp@ggwhyp·
8ae3eaa037285c812268cf5db98309f7555638e919dcbbe23e4d8e1f794d6d25
Português
0
0
5
3.1K