4 ms·
> I chained this bug with an n-day sandbox escape and flagged the v8CTF. https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/ https://serotav
by roywiggins 28d ago
> I chained this bug with an n-day sandbox escape and flagged the v8CTF.
https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/ https://serotav.github.io/Writeups/v8/when-sorting-leads-to-...
- socalgal2 27d agoThen what it was chained to is the real issue, not this one. The entire point of having webpages run in their own process is to prevent bugs like this one from doing worse. If you're claiming this bug is the bug that matters, you're effectively claiming they shouldn't need to run pages in their own process and just trust that there are zero bugs. No major browser does that. Not Firefox, not Safari, and not Chromium. that's why bugs in the webpage process pay out very little. Without a worse 2nd bug, they are less serious. Bugs that let you RCE outside the webpage process pay much higher.
- parineum 27d agoThen just call them both one exploit that allows arbitrary sandbox escape.
- TedDoesntTalk 27d agoSophisticated attacks will always leverage multiple vulnerabilities. That’s why you have to think of any vulnerability holistically, not in isolation.
- magicalist 27d agoI believe that means the v8 sandbox, not a renderer sandbox, based on the v8CTF reference.