Anthony @darkfloyd1216.bsky.social · 05/03/2026We got 7000 USD bounty from Google VRP. Nice, but hard work. Good and interesting desirable bug 😂🍀❤️ @wwkenwong @vxresearch 000
Reposted by AnthonySamuel Groß @saelo.bsky.social · 01/08/2025We released our Fuzzilli-based V8 Sandbox fuzzer: github.com/googleprojec... It explores the heap to find interesting objects and corrupts them in a deterministic way using V8's memory corruption API. Happy fuzzing!github.comAdd V8SandboxFuzzer · googleprojectzero/fuzzilli@675eccdThis is a basic fuzzer for the V8 Sandbox. It uses the memory corruption API to implement a random-but-deterministic (given a seed) traversal through the V8 heap object graph and corrupts some obje... 0257
Reposted by Anthonyhalvarflake.bsky.social @halvarflake.bsky.social · 10/09/2025I have often stated that well-implemented memory tagging will be a game changer for memory corruptions. And it seems that with the next iPhone it's finally here: security.apple.com/blog/memory-...security.apple.comBlog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security ResearchMemory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our adv... 45617
Reposted by AnthonySamuel Groß @saelo.bsky.social · 29/10/2025We derestricted crbug.com/382005099 today which might just be my favorite bug of the last few years: bad interaction between WebAudio changing the CPU's handling of floats and V8 not expecting that. See crbug.com/382005099#co... for a PoC exploit. Also affected other browsers 0177
Reposted by AnthonySamuel Groß @saelo.bsky.social · 09/12/2025More details: docs.google.com/document/d/1... Implementation: source.chromium.org/chromium/chr...docs.google.comV8 Sandbox - Bytecode VerificationV8 Sandbox - Bytecode Verification Author: saelo@ First Published: November 2025 Last Updated: November 2025 Status: Draft Visibility: PUBLIC Tracking Bug: crbug.com/461681036 This document is part ... 041
Reposted by AnthonySamuel Groß @saelo.bsky.social · 03/12/2025We derestricted a number of vulnerabilities found by Big Sleep in JavaScriptCore today: issuetracker.google.com/issues?q=com... All of them were fixed in the iOS 26.1 (and equivalent) update last month. Definitely some cool bugs in there!issuetracker.google.comGoogle Issue Tracker 064
Reposted by AnthonySamuel Groß @saelo.bsky.social · 24/11/2025I've uploaded the slides of my recent talk "JS Engine Security in 2025": saelo.github.io/presentation.... I think there'll also be a recording available at some point (otherwise I can make one as not everything's in the slides). Fantastic conference as usual, big thanks to the PoC Crew!saelo.github.io 02111
Reposted by AnthonySamuel Groß @saelo.bsky.social · 04/11/2025Some more cool JS Engine bugs found by Big Sleep were fixed in yesterday's Apple security updates: support.apple.com/en-us/125632 Technical details will be available soon at issuetracker.google.com/issues?q=com...support.apple.comAbout the security content of iOS 26.1 and iPadOS 26.1 - Apple SupportThis document describes the security content of iOS 26.1 and iPadOS 26.1. 174
Anthony @darkfloyd1216.bsky.social · 05/10/2025We are going to hold VXCON www.vxcon.hkvxcon.hkVXCONVXCON, we are glad to invite a few prominent speakers and researchers all over the world. They are frequent speakers of Blackhat, DEF CON, HITCON and in various global hacker and security conference. ... 000
Anthony @darkfloyd1216.bsky.social · 13/08/2025This time is a real thrilling announcement as our paper about template-based fuzzing for JavaScript engine is accepted in OOPSLA24-25. Thank you so much to every co-authors including Ken Wong, Dongwei Xiao, Dr. Daoyuan Wu Dr. Shuai Wang and Yiteng Peng. What a good evening! 020
Anthony @darkfloyd1216.bsky.social · 20/02/2025Congratulations to Carl Smith from v8 Security team and join Blackhat USA review board as guest reviewer. He is willing to share, open-minded, and a hardcore researcher and developer. @rwx.page 021
Anthony @darkfloyd1216.bsky.social · 29/01/2025The countries always attempt to hack into vendor platforms or apps, my idea is making a “Realistic Honeypot Platform” and let them in, capture as much as information about them and … cloud.google.com/blog/topics/...cloud.google.comAdversarial Misuse of Generative AI | Google Cloud BlogWe share our findings on government-backed and information operations threat actor use of the Gemini web application. 200
Anthony @darkfloyd1216.bsky.social · 11/01/2025Our first Chrome VRP bounty, it is an inspiration and keep going. 000
Anthony @darkfloyd1216.bsky.social · 19/12/2024We got our first Google Chrome bounty for minimum wage or McDonalds before Christmas 🎄. Getting money from Google is mission impossible. 000
Anthony @darkfloyd1216.bsky.social · 27/11/2024We are glad to complete VXCON. Thank you so much to every speakers, guest, and crew member to make it happen. #vxcon #vxrl 000
Reposted by AnthonySamuel Groß @saelo.bsky.social · 20/10/2023Here's another V8 sandbox design document, this time discussing how sensitive ("trusted") V8-internal objects (such as BytecodeArrays) can be protected: docs.google.com/document/d/1... This should be one of the last pieces of infrastructure required for the sandbox.docs.google.comV8 Sandbox - Trusted SpaceV8 Sandbox - Trusted Space Author: saelo@ First Published: October 2023 Last Updated: October 2023 Status: Living Doc Visibility: PUBLIC This document is part of the V8 Sandbox Project and discusses... 172
Reposted by AnthonySamuel Groß @saelo.bsky.social · 22/05/2024Finally got around to publishing the slides of my talk @offensivecon.bsky.social from ~two weeks ago. Sorry for the delay! The V8 Heap Sandbox: saelo.github.io/presentation... Fantastic conference, as usual! :) 045
Reposted by AnthonySamuel Groß @saelo.bsky.social · 13/11/2024Another big step towards becoming a security boundary: today we’re expanding the VRP for the V8 Sandbox * No longer limited to d8 * Rewards for controlled writes increased to $20k * Any memory corruption outside the sandbox is now in scope bughunters.google.com/about/rules/... Happy hacking!bughunters.google.comChrome Vulnerability Reward Program Rules | Google Bug HuntersATTENTION As of 4 February 2024, Chromium has migrated to a new issue tracker, please report security bugs to the new issue tracker using this form . Please see the Chrome VRP News and FAQ page for mo... 12810
Anthony @darkfloyd1216.bsky.social · 22/11/2024www.youtube.com/live/b9Ohamk...youtube.comYouTubeShare your videos with friends, family, and the world 000