@BlackHatOfficialYT
  @BlackHatOfficialYT
Black Hat | Reviving JIT Vulnerabilities: Unleashing the Power of Maglev Compiler Bugs on Chrome Browser @BlackHatOfficialYT | Uploaded 6 months ago | Updated 6 hours ago
...In this presentation, we will investigate the design principles of Maglev. Then we will share our experience in conducting vulnerability research and exploitation of the Maglev JIT Compiler based on our understanding of Turbofan. Firstly, we will compare and analyze the design principles of Maglev and Turbofan, thereby identifying the potential attack surface of Maglev. Next, we will demonstrate how to borrow security research experience from Turbofan to Maglev. We have improved the vulnerability exploration methods from three perspectives: Crash-based Fuzzing, Correctness-oriented fuzzing, and CodeQL in order to efficiently find vulnerabilities. Through this methodology, we found numerous bugs in Maglev, ultimately identifying and reporting 7 high-risk vulnerabilities. We will summarize and present the intriguing attack surface encountered during our research. Finally, we will demonstrate the exploitation of one of these vulnerabilities, achieving render RCE....

By: Bohan Liu , Zheng Wang xmzyshypnc

Full Abstract and Presentation Materials:
blackhat.com/eu-23/briefings/schedule/#reviving-jit-vulnerabilities-unleashing-the-power-of-maglev-compiler-bugs-on-chrome-browser-34437
Reviving JIT Vulnerabilities: Unleashing the Power of Maglev Compiler Bugs on Chrome BrowserBlack Hat Europe 2024 at the ExCel, London December 9-12Badge of Shame: Breaking into Secure Facilities with OSDPLLMs at the Core: From Attention to Action in Scaling Security TeamsHARry Parser and the Cursed Tracker: Breaking the Spell of Online Data CollectionThe Black Hat Europe Network Operations Center (NOC) ReportApples Predicament: NSPredicate Exploits on iOS and macOSBad Randomness: Protecting Against Cryptographys Perfect CrimePhysical Attacks Against SmartphonesThe Hole in Sandbox: Escape Modern Web-Based App Sandbox From Site-Isolation PerspectiveI Was Tasked With Enrolling Millions of Developers in 2FA - Heres What HappenedBingBang: Hacking Bing.com (and much more) with Azure Active Directory

Reviving JIT Vulnerabilities: Unleashing the Power of Maglev Compiler Bugs on Chrome Browser @BlackHatOfficialYT

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER