Ivan Fratric 💙💛

1.2K posts

Ivan Fratric 💙💛

Ivan Fratric 💙💛

@ifsecure

Tech lead and security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own. Backup @[email protected]

เข้าร่วม Ağustos 2011
208 กำลังติดตาม18.8K ผู้ติดตาม
ทวีตที่ปักหมุด
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
The slides for my Black Hat talk "XMPP Stanza Smuggling or How I Hacked Zoom" are now available at #xmpp-stanza-smuggling-or-how-i-hacked-zoom-26618" target="_blank" rel="nofollow noopener">blackhat.com/us-22/briefing…
English
4
69
280
0
Ivan Fratric 💙💛 รีทวีตแล้ว
Seth Jenkins
Seth Jenkins@__sethJenkins·
Just derestricted a now-fixed kernel bug in Pixel 10. I think this ranks as the most easily exploited kernel bug of all time😬 Thanks to @tehjh for collab'ing on this driver and full credits for noticing this bug in the first 5 minutes of auditing😂 project-zero.issues.chromium.org/issues/4634382…
English
5
43
188
15K
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
@cl4sm Yes, exactly, coverage is poor aproximation for state. I don't think better state approximation and mutational fuzzing are mutually exclusive, mutational fuzzer benefits from better state.
English
0
0
1
130
Wil Gibbs
Wil Gibbs@cl4sm·
@ifsecure Cool blog! The first problem feels like an issue with coverage being a poor approx. for program state. But approaches like IJON haven’t seen much success AFAIK in the real world. Do you think prob 1 gets fixed with better state approx or is the mutational fuzzer still needed?
English
1
0
1
402
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
Jackalope and Tinyinst have been working on arm64 macs for a while, but now you should also be able to run against arm64e binaries (i.e. binaries that ship with the os) with some modification to the system. For details, see github.com/googleprojectz…
English
2
22
122
7.4K
Ivan Fratric 💙💛 รีทวีตแล้ว
Natalie Silvanovich
Natalie Silvanovich@natashenka·
In the final part of his blog series, @tiraniddo tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphfh-…
English
0
54
190
20.3K
Ivan Fratric 💙💛 รีทวีตแล้ว
Natalie Silvanovich
Natalie Silvanovich@natashenka·
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/pixel-…
English
7
240
1K
114.8K
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
Project Zero has a new blog at projectzero.google and boy, do we have some some great content in store. For now, you can read two never published drafts as well as a guest post from Benoît from Threat Intelligence Group with an indepth analysis of an Android 0click exploit.
English
4
17
165
15.2K
Ivan Fratric 💙💛 รีทวีตแล้ว
Natalie Silvanovich
Natalie Silvanovich@natashenka·
We launched a redesigned Project Zero website today at projectzero.google ! To mark the occasion, we released some older posts that never quite made it out of drafts. Enjoy!
English
7
61
367
45.9K
Ivan Fratric 💙💛 รีทวีตแล้ว
Google VRP (Google Bug Hunters)
📢📢📢 Our Patch Rewards Program rules were updated to explicitly encourage batched submissions, and place every Google-filed OSS vulnerability explicitly into scope (thanks for your feedback). Interested in getting rewarded for your awesome OSS security work? g.co/prp
English
0
29
136
20.8K
Ivan Fratric 💙💛 รีทวีตแล้ว
Samuel Groß
Samuel Groß@5aelo·
V8 now has a JS bytecode verifier! IMO a good example for the benefits of a sandbox architecture: - Hard: verify that bytecode is correct (no memory corruption) - Easier: verify that it's secure (no out-of-sandbox memory corruption) Basically separates correctness from security
English
4
28
119
24.9K
Ivan Fratric 💙💛 รีทวีตแล้ว
Samuel Groß
Samuel Groß@5aelo·
We derestricted a number of vulnerabilities found by Big Sleep in JavaScriptCore today: issuetracker.google.com/issues?q=compo… All of them were fixed in the iOS 26.1 (and equivalent) update last month. Definitely some cool bugs in there!
English
2
34
175
17.8K
Ivan Fratric 💙💛 รีทวีตแล้ว
POC_Crew
POC_Crew@POC_Crew·
[POC2025] Talks are now UP ONLINE! Talks from #POC2025 are now publicly available on YouTube! Enjoy the sessions - see you again at POC2026! @pocsecurity" target="_blank" rel="nofollow noopener">youtube.com/@pocsecurity
English
2
50
158
29.4K