5 ms·
There's not a lot of context in this submission, but presumably it is being linked because the release notes for this CVE says "Google is aware of reports that
by mccr8 3y ago
There's not a lot of context in this submission, but presumably it is being linked because the release notes for this CVE says "Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild."
https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html https://chromereleases.googleblog.com/2024/01/stable-channel...
- deleted 3y ago[deleted]
- bri3d 3y agohttps://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve-2024-0517-out-of-bounds-write-code-execution/ https://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve... Here’s the exploit writeup.
- qingcharles 3y agoI wonder if they got a bounty from it?
- costco 3y agoExodus sells vulnerabilities to the government.
- mianos 3y agoTo quote their "ethics" statement: "We pride ourselves in our skillsets to parallel those of nation state hacking groups, and we tout that our expertise is unrivaled in our ability to discover and exploit vulnerabilities in a variety of product. Our intention as a Company is to provide this intelligence to US and Allied countries for their enterprise and governments to have a leg up over the malicious actors from around the world." Ouch.
- Leszek 3y agoThat's a different bug (CVE-2024-0517 vs CVE-2024-0519)
- bri3d 3y agoI’m pretty sure the chain is all three bugs. 517, 518, 519.
- Leszek 3y agoI'm pretty sure it isn't, the write up only uses 517 to get an arbitrary write primitive and then did a pretty standard chain into a sandbox escape via wasm (disclaimer - I work on V8).
- deleted 3y ago[deleted]
- bri3d 3y agoHmm. I also thought the type confusion in 518 was the same one from the blog post, but looking at the patch, it's not either. I think I stand corrected overall.