Uploaded March 2026 | Updated September 2026, 2 weeks ago
What does it take to fix a Firefox zero-day and ship the update to millions of users? We follow Mozilla from the disclosure room to the emergency release.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
part 1: youtube.com/watch?v=YQEq5s4SRxY
part 2: youtube.com/watch?v=uXW_1hepfT4
part 3: youtube.com/watch?v=NT1VCmJF3mU
part 4: youtube.com/watch?v=x4CUAuwoZVk
(Spoilers) Firefox Security Response to pwn2own 2025: blog.mozilla.org/security/2025/05/17/firefox-security-response-to-pwn2own-2025
CHAPTERS
00:00 - Back to the disclosure room
01:38 - Manfred explains the JIT bug
03:27 - Sharing the exploit and questioning the fuzzers
05:01 - Confirming the zero-day and a possible fix
05:39 - Browser sandboxes and renderer-only exploits
07:26 - Asking researchers about sandbox security
09:00 - Reproducing the exploit in JS Shell
10:21 - Mozilla's Saturday fire drill and fuzzing investigation
12:51 - From exploit demo to emergency patch
15:08 - How a chemspill rapid release works
16:21 - Repository trouble and release management
18:04 - The release timeline and a new record
18:54 - Installing the update and final thanks
19:28 - Mozilla security careers and resources
19:48 - Why security fundamentals still matter with AI
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Pwn2Own #Firefox #BrowserSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
What does it take to fix a Firefox zero-day and ship the update to millions of users? We follow Mozilla from the disclosure room to the emergency release.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
part 1: youtube.com/watch?v=YQEq5s4SRxY
part 2: youtube.com/watch?v=uXW_1hepfT4
part 3: youtube.com/watch?v=NT1VCmJF3mU
part 4: youtube.com/watch?v=x4CUAuwoZVk
(Spoilers) Firefox Security Response to pwn2own 2025: blog.mozilla.org/security/2025/05/17/firefox-security-response-to-pwn2own-2025
CHAPTERS
00:00 - Back to the disclosure room
01:38 - Manfred explains the JIT bug
03:27 - Sharing the exploit and questioning the fuzzers
05:01 - Confirming the zero-day and a possible fix
05:39 - Browser sandboxes and renderer-only exploits
07:26 - Asking researchers about sandbox security
09:00 - Reproducing the exploit in JS Shell
10:21 - Mozilla's Saturday fire drill and fuzzing investigation
12:51 - From exploit demo to emergency patch
15:08 - How a chemspill rapid release works
16:21 - Repository trouble and release management
18:04 - The release timeline and a new record
18:54 - Installing the update and final thanks
19:28 - Mozilla security careers and resources
19:48 - Why security fundamentals still matter with AI
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Pwn2Own #Firefox #BrowserSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.






![Understanding C Pointer Magic Arithmetic | Ep. 07
We debug the line that causes the heap overflow. And its a great opportunity to understand pointers in C.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-sudoedit/understanding-the-vulnerability
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
The full playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
Grab the files: https://github.com/LiveOverflow/pwnedit
The original disclosure: https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit
Episode 07:
CHAPTERS
00:00 - Intro & Motivation
00:46 - Create Debug Build
01:02 - The Crashing Location
01:43 - Scary Pointer Magic
02:10 - *to++ = *from
02:56 - Explaining: from++
04:03 - Explaining: *from
04:56 - Explaining: to++
05:23 - Explaining: *to = *from
05:54 - The Copy While Loop
06:26 - Explaining: from[0] vs *from
07:14 - The Bug!
08:35 - Wrong Allocation Size Calculated
09:30 - Unescape Logic
10:15 - Why though?
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BufferOverflow #BinaryExploitation #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Understanding C Pointer Magic Arithmetic | Ep. 07](https://i.ytimg.com/vi/zdzcTh9kUrc/mqdefault.jpg)