Mmm

597 posts

Mmm

Mmm

@hackyzh

Chrome GPU sandbox escape and Anroid Kernel Stuff.

Singapore Katılım Şubat 2018
599 Takip Edilen3.1K Takipçiler
Mmm
Mmm@hackyzh·
@roddux both,This is an obvious vulnerability; Claude could easily find it.
English
0
0
0
116
roddux
roddux@roddux·
@hackyzh So Claude found this bug? Or did you find it, and have Claude exploit it? :)
English
1
0
1
147
Mmm
Mmm@hackyzh·
@0vercl0k Most are reported by Google
English
0
0
0
224
Mmm
Mmm@hackyzh·
I'd like to ask everyone, after the Chrome VRP automatic update policy was implemented, are the bounties still being paid normally for vulnerabilities submitted before the new rules were introduced?🤣
English
1
0
5
1.4K
Mmm
Mmm@hackyzh·
@h3xr4bb1t Is it from Renderer RCE to Sandbox Escape? That price is way too low.
English
0
0
1
539
Mmm
Mmm@hackyzh·
@cybaqkebm same as pj0.I don't know why Google defined it this way; perhaps they didn't consider the case of 0-click?
English
0
0
0
248
Yusuf
Yusuf@cybaqkebm·
@hackyzh In which context? Google rates arbitrary code exec in media codecs as moderate severity, even Project Zero folks were surprised at some point. I stopped looking at 0-click. projectzero.google/2026/01/pixel-… #severity:~:text=Remote%20arbitrary%20code%20execution%20in%20a%20constrained%20context" target="_blank" rel="nofollow noopener">source.android.com/docs/security/…
English
2
0
3
338
Mmm
Mmm@hackyzh·
Found 1 android 0-click memory corruption vuln.However, it seems that the upstream issue was resolved in March.🤡Fortunately, it was just a minor OOB read.#0click
English
4
1
73
6.5K
Mmm
Mmm@hackyzh·
@h3xr4bb1t They need to create momentum.
English
0
0
0
814
HexRabbit
HexRabbit@h3xr4bb1t·
Honestly, with a little LLM help, I found variants, built a working PoC, and sent a polished patch to maintainer on the same day CopyFail dropped. So I’m curious why Xint didn’t find those variants before disclosure, assuming AI tools are used heavily in their workflow👀 Disclaimer: I’m an independent reporter and the patch author of the xfrm-ESP vulnerability, unrelated to the Dirty Frag post.
V4bel@v4bel

💥 Introducing "Dirty Frag" A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail. No race, no panic on failure, fully deterministic. ~9 years latent. Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more. Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation. Details: dirtyfrag.io

English
5
11
112
26.3K
Mmm
Mmm@hackyzh·
@calif_io These bounty are based old rules after new rules publish?
English
0
0
1
1.8K
Calif
Calif@calif_io·
Google paid us $57,000 for two bugs in Chrome. We’re not doing this for the bounty, but it’s always fun to get rewarded. These bugs were found using nothing fancier than a $20/month AI subscription. If you’re curious, come check out our talk at the Real World AI Security Conference at Stanford: seclab.stanford.edu/RealWorldAIsec/ We haven’t published the Chrome bugs in our MAD Bugs series. They work better as part of something even more fun, stay tuned!
Calif tweet media
English
19
96
1.1K
77.6K
Eduardo Vela
Eduardo Vela@sirdarckcat·
Just finished a really cool visit to Singapore! Where I met with a lot of the smartest folks here in the Vulnerability Research space. We are planning to build a new security hub in Singapore. And the first team we are building is going to be focused on.. 1/?🧵
Eduardo Vela@sirdarckcat

Well this was a productive trip. 😁

English
3
6
92
12.9K
Mmm
Mmm@hackyzh·
`The controlled read or controlled write poc must be included in your initial report - we will not consider submissions added at a later time.` That's ridiculous.
English
0
0
3
764
Mmm
Mmm@hackyzh·
#Demonstrating-controlled-read-or-write" target="_blank" rel="nofollow noopener">chromium.googlesource.com/chromium/src/+… Demonstrating controlled read or write Mojom interfaces to demonstrate controlled reads or controlled writes in privileged processes are available in vrp_flags.mojom.
English
2
5
41
5.6K
sakura
sakura@eternalsakura13·
@hackyzh It seems almost impossible to obtain sandbox escape bounties in the future.
English
1
0
2
1.5K
Mmm
Mmm@hackyzh·
@thedawgyg They are right.You cant use this flag when you report poc or exploit
English
0
0
0
99
dawgyg - WoH
dawgyg - WoH@thedawgyg·
8 weeks to be told a chrome exploit cant use the flag --single-process when launching chrome.... looks like moving on from google will be the right call
English
13
2
86
18.6K
Mmm retweetledi
Numen Cyber
Numen Cyber@numencyber·
Exploring Android ROOT via CVE-2025–21479 @numencyberlabs/exploring-android-root-via-cve-2025-21479-eca9fb7ca6e9" target="_blank" rel="nofollow noopener">medium.com/@numencyberlab
English
0
35
141
12.6K
Mmm retweetledi
Numen Cyber
Numen Cyber@numencyber·
CVE-2026–5283: Uninitialized GPU Memory Disclosure via Partial Clear in ANGLE (Chrome WebGL) @numencyberlabs/cve-2026-5283-uninitialized-gpu-memory-disclosure-via-partial-clear-in-angle-chrome-webgl-3740ca481149" target="_blank" rel="nofollow noopener">medium.com/@numencyberlab
English
1
20
78
9K
Mmm
Mmm@hackyzh·
@xaitax MSRC is like that; it can't compare to Google at all.
English
0
0
1
184
Alex
Alex@xaitax·
Almost two weeks after I asked for an update on my Windows Recall report, MSRC said their engineering team was in the “final stage of investigating.” A week later, they closed it as “not a vulnerability.” Based on that/their reasoning, they could have said that from day one. 🤷🏻‍♂️ Full write-up and release soon.
English
2
2
13
1.4K