4 Comments
User's avatar
Calif's avatar

You can find the PoCs here: https://github.com/califio/publications/tree/main/MADBugs/chrome.

Substack is crazy, it doesn't allow us to update the post.

jafork's avatar

Great work! I’m also working on exploiting GPU vulnerabilities to achieve a Chrome sandbox escape, but I haven’t yet found a way to bypass Address Space Layout Randomization (ASLR). I’m looking forward to the next article and hope it will provide a more detailed discussion of how information leaks can be used to defeat it.

Van Dang's avatar

Chưa đọc hết bài nhưng mà mình thấy 2 cái URL trong đoạn này có vẻ là đang bị sai rồi. Ae coi review lại xem.

"You can find the PoCs in poc/. To follow along, you'll want a build of d8 (the V8 developer shell) at the pinned commit above; the README.md covers building d8 and running each PoC."

Calif's avatar

We've fixed the links. Thanks!