Sign in

Samuel Groß

@saelo.bsky.social
1.1K followers 52 following 37 posts

Working on Project Zero, Big Sleep, and V8 Security. Personal account.

PostsRepliesMedia
Samuel Groß @saelo.bsky.social · 23/07/2026
Slides: saelo.github.io/presentation... Recording: youtu.be/maWnIKH3JQI?... Thanks Calif for hosting and the audience for listening and asking questions! :)
saelo.github.io
050
Samuel Groß @saelo.bsky.social · 14/07/2026
Rescheduled to this Thursday 17:00 CEST at youtube.com/live/yk1G5uL...
youtube.com
Meet the Hackers: Samuel Groß | State of Browser/JavaScript Engine Exploitation
YouTube video by Calif Official
050
Samuel Groß @saelo.bsky.social · 25/06/2026
Later today (17:00 CEST) I’ll do a public talk on browser security, hosted by calif.io. Livestream: youtube.com/live/iZE_iHc... There will also be a recording :)
calif.io
Calif | Hackers gonna hack, be prepped
Calif secures the AI you use every day. Red teaming and security engineering from the hackers trusted by Claude, Gemini, and Cursor.
140
Samuel Groß @saelo.bsky.social · 27/04/2026
Interesting talk coming up: www.offensivecon.org/speakers/202... I think there is sometimes a misconception that interpreters are somehow inherently more secure than JITs. Ultimately, it’s the optimizations added on top that matter. Both can get sufficiently complex and bug-dense (or not).
offensivecon.org
Nan Wang (sakura) & Ziling Chen (R1nd0) | OffensiveCon
191
Samuel Groß @saelo.bsky.social · 20/04/2026
The fuzzer that found project-zero.issues.chromium.org/issues?q=com... (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844 It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
project-zero.issues.chromium.org
Project Zero
0135
Reposted by Samuel Groß
Natalie Silvanovich @natashenka.bsky.social · 15/01/2026
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/pixe...
projectzero.google
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
15733
Samuel Groß @saelo.bsky.social · 09/12/2025
V8 now has a JS bytecode verifier! IMO a good example for the benefits of the V8 Sandbox architecture: - Hard: verify that bytecode is correct (no memory corruption) - Easier: verify that it is secure (no out-of-sandbox memory corruption) The sandbox basically separates correctness from security.
1204
Samuel Groß @saelo.bsky.social · 03/12/2025
We derestricted a number of vulnerabilities found by Big Sleep in JavaScriptCore today: issuetracker.google.com/issues?q=com... All of them were fixed in the iOS 26.1 (and equivalent) update last month. Definitely some cool bugs in there!
issuetracker.google.com
Google Issue Tracker
064
Samuel Groß @saelo.bsky.social · 24/11/2025
I've uploaded the slides of my recent talk "JS Engine Security in 2025": saelo.github.io/presentation.... I think there'll also be a recording available at some point (otherwise I can make one as not everything's in the slides). Fantastic conference as usual, big thanks to the PoC Crew!
saelo.github.io
02111
Samuel Groß @saelo.bsky.social · 04/11/2025
Some more cool JS Engine bugs found by Big Sleep were fixed in yesterday's Apple security updates: support.apple.com/en-us/125632 Technical details will be available soon at issuetracker.google.com/issues?q=com...
support.apple.com
About the security content of iOS 26.1 and iPadOS 26.1 - Apple Support
This document describes the security content of iOS 26.1 and iPadOS 26.1.
174
Samuel Groß @saelo.bsky.social · 29/10/2025
We derestricted crbug.com/382005099 today which might just be my favorite bug of the last few years: bad interaction between WebAudio changing the CPU's handling of floats and V8 not expecting that. See crbug.com/382005099#co... for a PoC exploit. Also affected other browsers
0177
Reposted by Samuel Groß
halvarflake.bsky.social @halvarflake.bsky.social · 10/09/2025
I have often stated that well-implemented memory tagging will be a game changer for memory corruptions. And it seems that with the next iPhone it's finally here: security.apple.com/blog/memory-...
security.apple.com
Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our adv...
45617
Samuel Groß @saelo.bsky.social · 12/08/2025
Some personal news: I'm thrilled to be moving back to Project Zero! Specifically I'll be joining the Big Sleep project to find vulnerabilities in JavaScript engines. We've already found and reported our first vulnerability in V8 last week: issuetracker.google.com/issues/43621...
issuetracker.google.com
Google Issue Tracker
1242
Samuel Groß @saelo.bsky.social · 01/08/2025
We released our Fuzzilli-based V8 Sandbox fuzzer: github.com/googleprojec... It explores the heap to find interesting objects and corrupts them in a deterministic way using V8's memory corruption API. Happy fuzzing!
github.com
Add V8SandboxFuzzer · googleprojectzero/fuzzilli@675eccd
This is a basic fuzzer for the V8 Sandbox. It uses the memory corruption API to implement a random-but-deterministic (given a seed) traversal through the V8 heap object graph and corrupts some obje...
0257
Samuel Groß @saelo.bsky.social · 09/07/2025
If you have a machine with PKEY support and somewhat recent Linux kernel you can now play around with hardware support for the V8 sandbox. When active, JS + Wasm code has no write permissions outside the sandbox address space. To enable, simply set `v8_enable_sandbox_hardware_support = true`.
1184
Samuel Groß @saelo.bsky.social · 02/07/2025
V8 Security is hiring in Munich, Germany: www.google.com/about/career... Great opportunity to work on some really hard and interesting problems in the security space!
google.com
Software Engineer III, V8 Security — Google Careers
0125
Samuel Groß @saelo.bsky.social · 03/06/2025
chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html Some cool things to note though: - the bug was mitigated via finch kill switch a day after the report from TAG - we also fixed the V8 Sandbox bypass within 7 days even though it's not yet considered a security boundary
chromereleases.googleblog.com
Stable Channel Update for Desktop
The Stable channel has been updated to 137.0.7151.68/.69 for Windows, Mac and  137.0.7151.68 for Linux which will roll out over the coming...
170
Reposted by Samuel Groß
Carl Smith @rwx.page · 04/02/2025
I’m very excited to announce that we at V8 Security have finally published our first version of Fuzzilli that understands Wasm! Go check it out at github.com/googleprojectzero/fuzzil…. While we still have a way to go in improving it, we think it shows a promising approach!
13116
Samuel Groß @saelo.bsky.social · 13/11/2024
Another big step towards becoming a security boundary: today we’re expanding the VRP for the V8 Sandbox * No longer limited to d8 * Rewards for controlled writes increased to $20k * Any memory corruption outside the sandbox is now in scope bughunters.google.com/about/rules/... Happy hacking!
bughunters.google.com
Chrome Vulnerability Reward Program Rules | Google Bug Hunters
ATTENTION As of 4 February 2024, Chromium has migrated to a new issue tracker, please report security bugs to the new issue tracker using this form . Please see the Chrome VRP News and FAQ page for mo...
12810
Samuel Groß @saelo.bsky.social · 07/06/2024
Thanks to events like Pwn2Own or our V8CTF (~= exploit bounty program), we now have more data about the types of bugs exploited in V8. Based on that, we've gathered some basic statistics: docs.google.com/document/d/1...
docs.google.com
Exploited V8 Bugs in 2024
Exploited V8 Bugs in 2024 Issue First Exploited Description Exploit requires V8 Sandbox Bypass Exploit requires JIT compilation Variant JavaScript or WebAssembly Introduced by Introduced in b/4149033...
130
Samuel Groß @saelo.bsky.social · 05/06/2024
And the recording is now also public: youtu.be/5otAw81AHQ0?... thanks @offensivecon.bsky.social!
youtu.be
OffensiveCon24 - Samuel Groß - The V8 Heap Sandbox
https://www.offensivecon.org/speakers/2024/samuel-gro%C3%9F.html
000
Samuel Groß @saelo.bsky.social · 22/05/2024
Finally got around to publishing the slides of my talk @offensivecon.bsky.social from ~two weeks ago. Sorry for the delay! The V8 Heap Sandbox: saelo.github.io/presentation... Fantastic conference, as usual! :)
045
Samuel Groß @saelo.bsky.social · 04/04/2024
Big day for the V8 Sandbox: * Now included in the Chrome VRP: g.co/chrome/vrp/#... * Motivation & goals discussed in a new technical blog post: v8.dev/blog/sandbox If there is ever a Sandbox "beta" release, this is it!
063
Samuel Groß @saelo.bsky.social · 15/02/2024
New V8 Sandbox design document is out: docs.google.com/document/d/1... This discusses how a hardware-based sandbox instead of the currently purely software-based one might look like in a somewhat distant future (if at all)
000
Samuel Groß @saelo.bsky.social · 19/01/2024
Some early performance numbers for the V8 Sandbox: looks like with most of the performance critical parts in place now, the overall performance cost of this future security boundary is only around 1% on popular benchmarks \o/ More results linked from chromium-review.googlesource.com/c/v8/v8/+/52...
Benchmark results on Speedometer2 showing that the overall performance impact of the V8 sandbox is only around 1% total
021
Samuel Groß @saelo.bsky.social · 08/12/2023
I've been meaning to write this for some time now and finally got around to it: a "V8 Sandbox Glossary" document that briefly explains the most important terms/concepts used for the sandbox and links to the respective design documents: docs.google.com/document/d/1...
docs.google.com
V8 Sandbox - Glossary
000
Samuel Groß @saelo.bsky.social · 30/11/2023
Another exciting step for the V8 sandbox: with crrev.com/c/5007733 BytecodeArrays are now the first objects to move into the new trusted heap space! Still a number of remaining issues around bytecode execution, but this fixes the long-standing issue that an attacker could directly corrupt bytecode
crrev.com
Gerrit Code Review
132
Samuel Groß @saelo.bsky.social · 20/10/2023
Here's another V8 sandbox design document, this time discussing how sensitive ("trusted") V8-internal objects (such as BytecodeArrays) can be protected: docs.google.com/document/d/1... This should be one of the last pieces of infrastructure required for the sandbox.
docs.google.com
V8 Sandbox - Trusted Space
V8 Sandbox - Trusted Space Author: saelo@ First Published: October 2023 Last Updated: October 2023 Status: Living Doc Visibility: PUBLIC This document is part of the V8 Sandbox Project and discusses...
172