Uploaded February 2026 | Updated September 2026, 2 weeks ago
What happens in the Pwn2Own disclosure room? Let's find out in part 2 of my short documentary about how Mozilla fixes zero-days.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Part 1: youtube.com/watch?v=YQEq5s4SRxY
Part 2: youtube.com/watch?v=uXW_1hepfT4
Part 3: youtube.com/watch?v=NT1VCmJF3mU
Part 4: youtube.com/watch?v=x4CUAuwoZVk
(Spoilers) Firefox Security Response to Pwn2Own 2025: blog.mozilla.org/security/2025/05/17/firefox-security-response-to-pwn2own-2025
CHAPTERS
00:00 - Heading into the disclosure room
01:54 - Waiting for ZDI to validate the submission
02:29 - Entering the room and sharing the exploit
02:46 - Promise.allSettled out-of-bounds write
04:20 - Reproducing and trying to bisect the bug
05:31 - Exploit stability and Firefox differences
07:20 - Leaving the disclosure room for Mozilla
08:21 - Coordinating the security incident
09:28 - ESR, Tor Browser, and six-year bisection
10:46 - Studying the exploit and improving fuzzing
11:49 - A prototype patch and variant search
12:24 - Why an open-source patch cannot land yet
13:14 - Risk assessment and overnight handoff
14:16 - Waiting for the second Firefox exploit
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Pwn2Own #Firefox #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
What happens in the Pwn2Own disclosure room? Let's find out in part 2 of my short documentary about how Mozilla fixes zero-days.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Part 1: youtube.com/watch?v=YQEq5s4SRxY
Part 2: youtube.com/watch?v=uXW_1hepfT4
Part 3: youtube.com/watch?v=NT1VCmJF3mU
Part 4: youtube.com/watch?v=x4CUAuwoZVk
(Spoilers) Firefox Security Response to Pwn2Own 2025: blog.mozilla.org/security/2025/05/17/firefox-security-response-to-pwn2own-2025
CHAPTERS
00:00 - Heading into the disclosure room
01:54 - Waiting for ZDI to validate the submission
02:29 - Entering the room and sharing the exploit
02:46 - Promise.allSettled out-of-bounds write
04:20 - Reproducing and trying to bisect the bug
05:31 - Exploit stability and Firefox differences
07:20 - Leaving the disclosure room for Mozilla
08:21 - Coordinating the security incident
09:28 - ESR, Tor Browser, and six-year bisection
10:46 - Studying the exploit and improving fuzzing
11:49 - A prototype patch and variant search
12:24 - Why an open-source patch cannot land yet
13:14 - Risk assessment and overnight handoff
14:16 - Waiting for the second Firefox exploit
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Pwn2Own #Firefox #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
![Why Pick sudo as Research Target? | Ep. 01
A serious sudo vulnerability had just been announced, but how do researchers find bugs like it? This first episode explains why sudo is an interesting target, prepares a reproducible research environment, and begins an AFL fuzzing strategy that immediately runs into practical problems.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-sudoedit/sudoedit-introduction
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
RESOURCES
Text version: https://liveoverflow.com/why-pick-sudo-research-target-part-1/
Episode files: https://github.com/LiveOverflow/pwnedit/tree/main/episode01
Full playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
CHAPTERS
00:00 - Intro
01:48 - Prepare the System
03:57 - How to Pick a Research Target?
05:57 - Choose the Strategy: Fuzzing
09:27 - Fuzzing argv[] With AFL
13:00 - Running Into the Next AFL Problem
14:51 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BinaryExploitation #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Why Pick sudo as Research Target? | Ep. 01](https://i.ytimg.com/vi/uj1FTiczJSE/mqdefault.jpg)









