Mmm

577 posts

Mmm

Mmm

@hackyzh

Singapore Katılım Şubat 2018
584 Takip Edilen3K Takipçiler
Mmm
Mmm@hackyzh·
Interesting bugs, from Chrome to kernel crash on some device without MTE.
English
0
3
71
7.6K
Mmm
Mmm@hackyzh·
@2st___ chrome?
English
1
0
1
878
Qinrun Dai
Qinrun Dai@2st___·
Another RCE is born. Finding a useful infoleak is 10x harder than the OOB write. Hoping to catch this year's BlackHat :)
Qinrun Dai tweet media
English
3
11
118
8.1K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
@hackyzh They also missed my bisect bonus and report quality bonus. I think its bc I accidentally made several of the comments protected (it auto did and I didn't know i could change at first). So gonna ask them to look at it again.
English
1
0
9
1K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
That was a bit disappointing... Just got $7000 for my Chrome heap overflow read. And $11,000 for the heap overflow write.... no bonus for report quality... ignored the bisect that was included... $11k for RCE in the renderer seems a bit low... so time for a new target...
English
20
1
244
18.4K
Mmm
Mmm@hackyzh·
@thedawgyg You can argue with them.Sometime they cloud make mistakes.
English
1
0
1
1K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
@hackyzh Yes I can. I provided poc with proven RIP control. Pc control. Was full write any value i want any location any size.
English
1
0
6
1.7K
Mmm
Mmm@hackyzh·
@ret2happy 打马干啥,25w😆
中文
0
0
1
359
Mmm retweetledi
Security Bug Aggregator
Security Bug Aggregator@BugsAggregator·
[446722008][reward: $100000] heap-use-after-free in content::indexed_db::Database::connections_ when force_closing_ is true crbug.com/446722008
English
2
43
289
172.6K
Fat
Fat@fattselimi·
@hackyzh Here are 15 reputation points thank you for the commitment
English
1
0
2
203
Mmm
Mmm@hackyzh·
MSRC is really ridiculous. I don't know if they're refusing bounties or what. I accidentally discovered and submitted OOB Write and UAF vulnerabilities, and they either said the vulnerabilities were low-risk or that they couldn't reproduce them in the latest version.
Mmm tweet mediaMmm tweet media
English
8
4
62
18.6K
Fat
Fat@fattselimi·
@hackyzh They are really awful regarding bounties i found bug in microsoft.com main site and they refused to pay me bounty.
English
1
0
6
948
Mmm
Mmm@hackyzh·
Comparatively, I prefer Google. In the past, when I submitted vulnerabilities to Google, at least they would keep in touch with me. After Microsoft shut down its services, they rarely responded anymore.
English
1
0
7
1.3K
Mmm
Mmm@hackyzh·
So, it's best not to submit vulnerabilities to MSRC, since they don't seem to care much about vulnerabilities and are even less concerned about the security of their own products.🤡
English
0
1
18
1.3K
Mmm
Mmm@hackyzh·
@farazsth98 The highest in chrome is 250K
English
0
0
1
343
Mmm
Mmm@hackyzh·
@farazsth98 Theoretically, it should be reproducible.
English
0
0
0
159
Faith 🇧🇩🇦🇺
Faith 🇧🇩🇦🇺@farazsth98·
@hackyzh Hmm ok I took a quick look at the code, there are some changes, but nothing that should affect the PoC, so I think I can definitely get it working in QEMU on that same kernel version. But yeah I don't have a real device to test against so I'll finish the exploit in QEMU later 🥲
English
1
0
1
217
Faith 🇧🇩🇦🇺
Faith 🇧🇩🇦🇺@farazsth98·
In my previous post about CVE-2025-38352, I used a kernel patch to extend the race window to help trigger the vulnerability. I've since improved it to work without the kernel patch. @hackyzh 👀 I also wrote a "Part 2" of the blog post. It's linked at the end of this thread!
Faith 🇧🇩🇦🇺 tweet media
Faith 🇧🇩🇦🇺@farazsth98

After reading @streypaws blog post on CVE-2025-38352, I ended up writing my own PoC for it. I also wrote a blog post on my approach to analyzing and recreating the PoC. Hopefully it is useful to others! See link in the reply tweet below!

English
3
23
92
15K
Mmm
Mmm@hackyzh·
@farazsth98 Linux localhost 5.10.157-android13-4-00001-g5c7ff5dc7aac-ab10381520
English
1
0
1
109
Mmm
Mmm@hackyzh·
@farazsth98 Not sure.I will continue the investigation.
English
1
0
0
68
Faith 🇧🇩🇦🇺
Faith 🇧🇩🇦🇺@farazsth98·
@hackyzh Oh, hmm.. I don't have any devices to test with 🥲 Do you have any idea what the issue could be? I wonder if the race window is not long enough because it can't create enough threads or if it's something else
English
1
0
0
87