>_0xFORUM
Sign in

Type confusion in a JS engine — reading the advisory like a grown-up

in Exploits11 replies5.4k views

Public Chromium bug, patched. The advisory is enough to hunt the old object shape. It is not enough to write an exploit, and that is good.

If your 'notes' are a heap spray, you are in the wrong thread and maybe the wrong forum.

Refs: Chromium security · CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

@zenit

This matches a public n-day class from last patch Tuesday. The load-bearing line: Public Chromium bug, patched. Patched class only. Hunt the

I still keep a paper notebook for this kind of note. You wrote «Public Chromium bug, patched». That is the sentence I keep. If the thread slides toward a live target, lock it. I will report it. Took me 12 hours the first time.

I would have written the opposite conclusion a year ago. You wrote «Public Chromium bug, patched». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. Version in my shot: current lab snapshot, not last year's blog.

@opzsec

I would have written the opposite conclusion a year ago. You wrote «Public Chromium bug, patched». That is the sentence I keep. Date your he

Quote the bytes or sit down. I disagree with the tone, not the bytes. «Type confusion in a JS engine — reading the advisory like a grown-up» — specifically Public Chromium bug, patched. A saturating add that hangs is not a complete patch. Hunt the hang too. I reproduced it on lab build 1296.

Came back to this after a coffee. Still hold. On «Type confusion in a JS engine — reading the advisory like a grown-up»: Public Chromium bug, patched. Date your heap notes. 2012 grooming diagrams are history. I wrote a 12-line script and then threw it away. The listing was enough.

@reconx

Came back to this after a coffee. Still hold. On «Type confusion in a JS engine — reading the advisory like a grown-up»: Public Chromium bug

You are treating a checksum as a signature again. Please keep the hashes and drop the mystery zips. The load-bearing line: Public Chromium bug, patched. system() on a user path is the class. execve with argv is the patch. Can you quote the offset instead of the graph screenshot? My note id for this: db-03.

@samueljay

Please keep the hashes and drop the mystery zips. The load-bearing line: Public Chromium bug, patched. system() on a user path is the class.

I still keep a paper notebook for this kind of note. The load-bearing line: Public Chromium bug, patched. A saturating add that hangs is not a complete patch. Hunt the hang too. I will +rep a listing and −rep a vibe. That is the deal.

@shola_k

I still keep a paper notebook for this kind of note. The load-bearing line: Public Chromium bug, patched. A saturating add that hangs is not

You skipped isolation and then asked why the box is dirty. That is on you. This is the writeup I wanted when I was stuck. You wrote «Public Chromium bug, patched». That is the sentence I keep. A saturating add that hangs is not a complete patch. Hunt the hang too. Took me 12 hours the first time.

Did this on ARM64 last week — same shape, different pain. «Type confusion in a JS engine — reading the advisory like a grown-up» — specifically Public Chromium bug, patched. system() on a user path is the class. execve with argv is the patch. Same class as the June thread, different binary.

@sysx

Did this on ARM64 last week — same shape, different pain. «Type confusion in a JS engine — reading the advisory like a grown-up» — specifica

I am not moving this to DMs so you can yell. Stay on the class. Came back to this after a coffee. Still hold. «Type confusion in a JS engine — reading the advisory like a grown-up» — specifically Public Chromium bug, patched. system() on a user path is the class. execve with argv is the patch. Took me 12 hours the first time.

Came back to this after a coffee. Still hold. On «Type confusion in a JS engine — reading the advisory like a grown-up»: Public Chromium bug, patched. Date your heap notes. 2012 grooming diagrams are history. Hash of the public file, or are we arguing a shape? I wrote a 12-line script and then threw it away. The listing was enough.

@vultr

Came back to this after a coffee. Still hold. On «Type confusion in a JS engine — reading the advisory like a grown-up»: Public Chromium bug

That is not what the listing shows. You are arguing a vibe. This matches a public n-day class from last patch Tuesday. The load-bearing line: Public Chromium bug, patched. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Same class as the March thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.