xvonfers Profile Banner
xvonfers Profile
xvonfers

@xvonfers

Followers
3K
Following
3K
Statuses
4K

Browser & *nix VR. Ex SIGINT

Russia
Joined August 2023
Don't wanna be here? Send us removal request.
@xvonfers
xvonfers
6 months
V8 Sandbox escape/bypass/violation and VR collection
3
58
239
@xvonfers
xvonfers
2 days
RT @IOActive: Check out our Silicon Team's latest research paper!
0
4
0
@xvonfers
xvonfers
2 days
RT @IOActive: Download our FREE e-book, 'The State of Silicon Chip Hacking,' to learn about Silicon microchip hacking, a highly specialized…
0
2
0
@xvonfers
xvonfers
2 days
@ilove2pwn_ One of the few songs in my playlist that I like both in the original and variations, it doesn't bother me during research and I listen in any mood, remembering the past and thinking about the present.
1
0
4
@xvonfers
xvonfers
2 days
RT @wh1ant: I'm looking for a remote job. I was a N-day and 0-day researcher. I found vulnerabilities from browsers when I worked at a comp…
0
39
0
@xvonfers
xvonfers
2 days
[$55000](CVE-2024-8904)[365376497][wasm][jspi] 😅Add regression test
@xvonfers
xvonfers
2 months
🔥🔥🔥 [$55000](CVE-2024-8904)[365376497][wasm][jspi]JSPI stack switching breaks lazy deoptimization guarantees -> type confusion in V8 is now open with PoC(bypass stable map code dependencies) and exploit(rce + v8sbx escape[361862752])
Tweet media one
0
6
42
@xvonfers
xvonfers
2 days
RT @thatjiaozi: I almost did it! I found an exploitable buffer oob in qemu. No cve tho due to canokey being a development only device tho…
0
2
0
@xvonfers
xvonfers
3 days
[374811614][$10000][maglev]DCHECK failure in id_ != kInvalidNodeId in maglev-ir.h PoC:
0
0
6
@xvonfers
xvonfers
3 days
[352689356][sandbox] @0x10n
Tweet media one
@xvonfers
xvonfers
4 months
[352689356][sandbox]V8sbx bypass, AAR/W via wasm function signature confusion in TurboFan call_ref with in-sandbox exploit primitives Repro: @0x10n
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
0
0
@xvonfers
xvonfers
3 days
[395062211][sandbox] Only use TrustedPointerPublishingScopes on main thread
0
0
3
@xvonfers
xvonfers
3 days
RT @axboe: The networking side of the io_uring receive zero-copy support was finally merged, it's queued for the 6.15 kernel. See this merg…
0
20
0
@xvonfers
xvonfers
3 days
(CVE-2024-34730)[308429049][Bluetooth]HID profile accepted any new incoming HID connection. Even when the connection policy disabled HID connection, remote devices could initiate HID connection
@xvonfers
xvonfers
1 month
Android Security Bulletin January 2025 6 crit vulns...
Tweet media one
Tweet media two
0
0
0
@xvonfers
xvonfers
3 days
😅That's interesting, I'll try a chain with... (CVE-2024-34722)[251514170]When pairing with BLE legacy pairing initiated from remote, authentication can be bypassed(in SMP)
@xvonfers
xvonfers
1 month
Android Security Bulletin January 2025 6 crit vulns...
Tweet media one
Tweet media two
0
0
7
@xvonfers
xvonfers
3 days
Tweet media one
@xvonfers
xvonfers
9 days
It's not even funny anymore, it's been so long, even though links have already been found, but there is still no update on the newsletter page (there are no links to commits added).
1
0
6
@xvonfers
xvonfers
3 days
🤣🤣🤣 (CVE-2025-0098)[367266072]Malicious app could register the organizer via one-way binder call to disguise as running on pid 0(activity token leaked to another process)
Tweet media one
@xvonfers
xvonfers
6 days
Android Security Bulletin February 2025
0
0
7
@xvonfers
xvonfers
3 days
😂😂😂 (CVE-2025-0096)[356630194] "Fix malloc buffer size": - *NewTlv = (uint8_t*)malloc(8 * sizeof(uint8_t)); + *NewTlv = (uint8_t*)malloc(9 * sizeof(uint8_t)); Introduced here:
Tweet media one
Tweet media two
@xvonfers
xvonfers
6 days
Android Security Bulletin February 2025
2
6
37
@xvonfers
xvonfers
3 days
[394402574][turboshaft] Fix wrong comparison in DCHECK function foo(x) { let v = 0; [2, 3].forEach(y => v += y + x); } %PrepareFunctionForOptimization(foo); foo(3); foo(3); %OptimizeFunctionOnNextCall(foo); foo();
Tweet media one
0
1
2
@xvonfers
xvonfers
3 days
[394767640][wasm][type-reflection] Fix nested WasmJSFunction
@xvonfers
xvonfers
6 days
🤔 [393632542][wasm][type-reflection] Do not unwrap WasmJSFunctions on import Regress test: Flatten nested WasmJSFunctions on import Regress test:
0
0
1
@xvonfers
xvonfers
3 days
[388844115, 394650781][turbofan] Fix related to the TypedArray type const a = new Uint8Array(); function foo() { return ArrayBuffer.isView(a); } assertTrue(foo()); %PrepareFunctionForOptimization(foo); %OptimizeFunctionOnNextCall(foo); assertTrue(foo());
0
0
4
@xvonfers
xvonfers
3 days
WIP: improve the type hint mechanism in sparkplug
Tweet media one
0
1
6
@xvonfers
xvonfers
3 days
[42202660]Tracking bug for enabling 256-bit vector for WASM SIMD
0
1
2