6 min read
CVE-2021-30632: Chrome V8 Type Confusion -> RCE
Analysis of a type confusion vulnerability caused by a missing global-property Map stability check in V8's TurboFan JIT, plus a Windows RCE exploit
Read full articleTags
Analysis of a type confusion vulnerability caused by a missing global-property Map stability check in V8's TurboFan JIT, plus a Windows RCE exploit
Read full articleAnalysis of CVE-2021-26411, a UAF vulnerability in the Internet Explorer JavaScript engine that the Lazarus Group exploited in real-world attacks
Read full articleA step-by-step breakdown of a V8 OOB exploit: type confusion, addrOf/fakeObj primitives, and WASM RWX shellcode execution
Read full article