TALKS & SPEAKERS

Two days of conferences | 16 talks | 20 speakers

Click on a talk to see the speaker's presentation

Opening Keynote

Bruce Dang, Thai Duong

The Cloud Runs on GPUs. So Do We: Breaking Out Through GPU Drivers

Lei Lu, Ji'an Zhou

Consoling Windows: Racing the Console Driver to escape the sandbox

Guillaume André

Coruna vax - Deep dive and takeaways

Littlelailo

Dirty Pedit: Semantic Variant Hunting for Root in Under a Second

Rajat Gupta

Double Agents: Weaponizing Synchronization Mechanisms to Reliably Exploit Race Conditions

Robert Huey

Freedom of the Cache - Democratizing Page Caches With RDMA

Philip Tsukerman

Full Root: Kernel-driver page uaf and confused-deputy vuln in Samsungs DualDAR subsystem

Lukas Maar

The Last Proof of Human Craft: Forging a Microsoft Edge Full Chain with Logic Bugs Only!

Orange Tsai

MTEscape: Bypassing ARM's Asynchronous MTE with General Memory Corruption Vulnerabilities

Kyeongmin Kim, Insu Yun

One Parser, Two Bugs, Many Routers: Exploiting Broadcom WiFi Across eCos and Linux

Quentin Kaiser

Parcel Security in Android: From Mismatch to Use-After-Free

Yang Kudurshian, John Wu

Reinventing the vPhone — A Next-Generation iOS Security Research Platform

Maximilian Paß

Revisiting SecureROM Adventures

Steven De Franco

Wasm Spills The Beans on Chrome and Safari

Javier Jimenez

When Picos Attack – USB Exploit Engineering

Alex Plaskett

Opening Keynote

Abstract

2026 has been the year of AI for vulnerability research. Within a period of a few months, frontier models such like Mythos and the likes have changed the entire research community and its experts’ outlook on computer security. The AI is simultaneously a security expert in firmware, kernels, browsers, web applications, cryptography, network security, reverse engineering … and has the patience to happily audit 1,000,000+ lines of Reactive Java SpringBoot code without needing drugs or mental therapy. How are we suppose to co-exist with it in this new world? In this keynote, we will share our experiences in using AI for vulnerability research and discuss its strengths and limitations. We will also discuss how the industry may need to rethink and change its approaches disclosure, detection/response, and software updates.

Speakers

Bruce Dang

Calif.io
@brucedang

Bio

Bruce Dang is a failed recluse who has been dabbling with computer for a few years. He started his security career in the primordial days of the Microsoft Security Response Center (MSRC) when it averaged three or 4 Windows bugs per month. Along the way, he analyzed Stuxnet and wrote a popular children's book called _Practical Reverse Engineering_ with some friends. After realizing the impermanence of Windows, he seeked out the elders at Apple and was re-educated in computer security. As a novice mendicant at Apple, he learned the real challenges of privacy, security, and debugging without attachment or anger. His single-minded pursuit was interrupted by the iconoclasts at Calif.io; they convinced him that AI is the only true path to enlightenment. Since then, he has been studying the endless sacred scriptures of Claude. He has not reached AGI.

Thai Duong

Calif.io
@XorNinja

Bio

Thai was born in Saigon and grew up on the Internet. He has spent most of his adult life breaking things for a living. During 12 years at Google, he worked on security and cryptography, helping create tools such as Google Tink and Project Wycheproof. Before that, he helped discover the SSL attack trilogy: BEAST, CRIME, and POODLE. Together with Juliano Rizzo, he won a Pwnie Award for Best Server-Side Bug. These days, Thai is part of Calif, a security research firm specializing in AI security. His official title is CEO, which, according to Dilbert, makes him the least competent person in the company.

The Cloud Runs on GPUs. So Do We: Breaking Out Through GPU Drivers

Abstract

The AI boom has made GPUs one of the most critical resources in modern cloud infrastructure. From training and fine-tuning to large-scale inference, AI workloads increasingly depend on cloud-hosted GPUs, making them a foundational component of today’s computing ecosystem.

While GPU security research is well established in the mobile world, where GPU driver vulnerabilities have repeatedly enabled privilege escalation, discrete GPUs powering cloud environments have received far less attention. This raises an important question: can cloud GPUs introduce security risks beyond those traditionally seen on mobile platforms?

To answer this, we analyzed the GPU driver stacks of two major GPU vendors, which together power virtually all cloud GPU deployments. Our research shows that the impact of cloud GPU vulnerabilities can be significantly more severe than mobile privilege-escalation bugs. In GPU-enabled cloud environments, host GPU devices are routinely exposed to untrusted containers running AI workloads. Because GPU drivers operate in the kernel, vulnerabilities within them can provide powerful exploitation primitives that lead directly to full container escape.

Speakers

Lei Lu

@llfamsec

Bio

Lei Lu is an independent security researcher. He has focuses on application and system security. He has reported many vulnerabilities to Linux, NVIDIA, Apple, Microsoft, etc. He has presented at PHDays 2025.

Ji'an Zhou

@azraelxuemo

Bio

He focuses on web security, cloud security, AI security and kernel security. His research has benefited numerous prominent vendors including Google, Apple, and Microsoft. He has delivered talks at Black Hat Europe 2024, Zer0Con 2025, Off-by-One Con 2025, Black Hat USA 2025, DEF CON 33, Zer0Con 2026, Black Hat Asia 2026, SAFACON 2026, deepsec.cc, and DEF CON 34.

Consoling Windows: Racing the Console Driver to escape the sandbox

Abstract

The Windows Console Driver is a small kernel driver that acts as the link between console applications and the process hosting their windows. Since its introduction in Windows 8.1, its attack surface has been overlooked. This talk aims to fix this by presenting a simple bug leading to privilege escalation, and more surprisingly, escape from one of the most hardened sandboxes in Windows.

In this session, we will first give a quick overview of the console architecture on Windows and the role played by the Console Driver. We will then introduce the vulnerability and the challenges we faced during its exploitation, notably winning a very precise race condition and transforming a limited write primitive into a SYSTEM shell.

Afterwards, we will explore the different sandbox mechanisms implemented in Windows and demonstrate how this bug is reachable from heavily restricted contexts, allowing us to escape the LPAC sandbox by adapting our exploitation primitives to work in those constraints.

Speakers

Guillaume André

Synacktiv
@yaumn_

Bio

Guillaume is a penetration tester and security researcher working at Synacktiv. During his career, he developed a healthy addiction to Windows systems and their internals. He is also passionate about Active Directory security, a topic on which he gathered solid knowledge through several Red Team engagements and internal pentests.

Coruna vax - Deep dive and takeaways

Abstract

Shortly after GTIG and iVerify released blogposts on the Coruna exploit kit I obtained access to a sample. The next couple weeks felt like the good old days, staying up late with friends to defeat obfuscation, reverse the chains and finally build up RCAs of the bugs. This talk will feature some of that analysis as well as takeaways from it.

Speakers

Littlelailo

@littlelailo

Bio

Interested in RE and pwning stuff | hacking *OS atm

Dirty Pedit: Semantic Variant Hunting for Root in Under a Second

Abstract

Page-cache corruption bugs are unusual because they can turn read access into the ability to modify the in-memory contents of file-backed pages, enabling local privilege escalation without changing data on disk. After Dirty COW, Dirty Pipe, Copy Fail, and Dirty Frag, most variant hunting focused on straightforward syntactic copies of known paths. This talk shows how a semantic variant-hunting workflow produced three new unprivileged root exploits: skb_shift and GRO flag loss (common CVE-2026-43503) — which bypass both existing patches — and the flagship, Dirty Pedit (CVE-2026-46331), a previously unknown route to deterministic root in under one second via Linux traffic control.

Our approach decomposes the entire Dirty COW to Dirty Frag exploitation chain into three independently queryable stages: Entry, Violated Invariant, and Writer. To make this work at scale, we built QuerySmith (tells you what’s valid, not just what’s wrong) and QueryLens (tells you exactly which predicate is failing). Together they enabled a focused campaign of 16 targeted CodeQL queries across the kernel, producing three unprivileged root exploits. The flagship, Dirty Pedit, required wiring results from queries targeting independent stages: one identified a novel arithmetic mismatch between skb_ensure_writable() and tcf_pedit_act() — a signed-to-unsigned wraparound creating a COW gap — while another surfaced tcf_pedit_act as a novel writer primitive: a direct 4-byte page-cache write via skb_store_bits, independent of any crypto subsystem which is a known writer primitive in the dirty series. Separately, they’re curiosities. Together, they’re root in under one second.

Beyond the exploit itself, the talk gives attendees a practical method for semantic variant hunting: decompose exploit chains into queryable stages, use deterministic feedback to debug query behavior, and intersect independently interesting results to uncover exploitable paths that syntactic searches miss. All findings were responsibly disclosed and patches have merged upstream. The talk concludes with a live or recorded demo.

Speakers

Rajat Gupta

Qualcomm
@z3ta_rjt

Bio

Rajat Gupta finds and exploits vulnerabilities across browsers, Linux kernel, and Windows kernel drivers, and develops systems for systematic vulnerability discovery at scale. His variant analysis methodology turned one kernel root cause into three universal local privilege-escalation exploits. Previously, he built Popkorn with UCSB Shellphish — discovering four privilege-escalation vulnerabilities in Windows kernel drivers using targeted symbolic execution (ACSAC 2022), co-authored browser security research with Georgia Tech SSLab, and competed in DEF CON CTF Finals three years running. When not breaking kernels at Qualcomm, he's hunting perfect backhand loops at the table tennis table, trails with elevation gain, or the spiciest dish on the menu.

Double Agents: Weaponizing Synchronization Mechanisms to Reliably Exploit Race Conditions

Abstract

Semaphores, mutexes, and other synchronization primitives are designed to prevent race conditions. Used improperly, they can instead let subtle vulnerabilities slip through the cracks. Race conditions are notoriously difficult to land, but what if the very constructs meant to protect a program could be turned against it, letting an attacker consistently win the race?

In this presentation, we will explore a previously unpublished exploit chain targeting NVIDIA Linux Open GPU Kernel Modules, resulting in local privilege escalation and container escape. Beyond attacking insufficient synchronization, we will turn these synchronization primitives against the software they were designed to protect and achieve dependable kernel code execution.

We begin with a timing-based side-channel attack on a buggy GPU semaphore interface. Leveraging an Out-of-Bounds read, we will leak kernel memory, bit-by-bit. Next, we will target a Time-Of-Check to Time-Of-Use vulnerability, caused by faulty use of a readers-write lock. This bug manifests as a Use-After-Free, with an unconscionably tight reclaim window measured at merely a couple hundred CPU ticks. Furthermore, losing the race triggers a kernel panic and system reboot, neutralizing a probabilistic “spray and pray” approach.

With help from a few million hash collisions and a well-timed heap spray, we will count on our Double Agents to turn this pipe dream of a race condition into a reliable exploit (which will be demonstrated!). Experience a race that can’t be lost as we escape the NVIDIA Container Toolkit.

Speakers

Robert Huey

@RobertJHuey

Bio

Robert is a reverse engineer and vulnerability researcher with an interest in operating systems and low-level software.

Freedom of the Cache - Democratizing Page Caches With RDMA

Abstract

Linux Page caches save you the hassle of going to your storage device every time you need to access a file.  Unfortunately, we live in a society that doesn’t let us regular people modify most of those, leaving us with read-only access to files that we ourselves have opened,  in our own process! Sometimes even mapped into our own process memory space!
Fortunately, some recent developments have given us a few ways to circumvent this injustice, supplying the people with some page cache corruption vulnerabilities such as Copy Fail and its several siblings.
In our talk, we will focus on a more distant cousin of this pattern, targeting the RDMA subsystem of Linux, which is usually available in the kinds of multi-GPU systems which may most benefit from a bit of extra democracy. During this session, we will go over the generalized flaw which might lead to this kind of vulnerability, some internals of RDMA on Linux, and the actual vulnerability and 100% reliable LPE exploit we developed for it.

Speakers

Philip Tsukerman

Palo Alto

Bio

Several years ago, Philip decided that computers are in fact really cool, and that he wants to spend a lot of time breaking and protecting them. Computers, on the other hand, don't share a similar sentiment about Philip and frankly consider him to be a bit of a nerd. He currently leads a research team at Palo Alto Networks.

Full Root: Kernel-driver page uaf and confused-deputy vuln in Samsungs DualDAR subsystem

Abstract

Samsung’s Dual Data-at-Rest (DDAR) encryption is a Knox kernel component, absent from mainline Android. It wraps sensitive files in a second encryption layer above Android’s file-based encryption so the most sensitive data stays sealed. To do this, its /dev/dd driver hands each crypto request’s metadata page to a userspace crypto task through a shared mapping and performs encryption and key handling there. However, this also opens a new attack surface across Samsung’s flagship Galaxy S and Z series.

In this talk, I show that the DDAR subsystem introduces two vulnerabilities that together allow rooting every recent flagship Galaxy S and Z device. The first is an improper access-control flaw: a sandbox escape that injects code from an untrusted_app context into the privileged dualdard system daemon. The second is a mapping-lifetime bug that hands userspace read/write access to physical memory the kernel has already freed.

I present the complete chain from a zero-permission app to root on a late-August-updated Galaxy S26 (kernel 6.12.38) and S26 Ultra (kernel 6.12.30), both on Android 16 with verified boot and a locked bootloader. I developed it almost blind, with only a Magisk-rooted S23 (Android 14, kernel 5.15.148) as a debuggable testbed. The strategy is highly reliable and portable: moving between the S23 and both S26 variants took little more than adapting offsets and data-structure differences that can be pre-computed per firmware. I further confirmed from the released sources that the same vulnerable code ships unchanged on the Galaxy S23 through S26 and Z Fold7, so a single weaponized chain could cover them all. Along the way, the chain yields new insight into defeating hardened defenses such as SELinux as well as Samsung’s RKP and DEFEX.

Speakers

Lukas Maar

Calif.io

Bio

I am Lukas Maar, a Security Researcher at Calif and a Senior Security Researcher at ISEC, TU Graz. My work focuses on low-level security, particularly the Linux and Android kernels.

I have discovered multiple zero-day vulnerabilities in the Linux kernel, the Android kernel, and Android applications. My research also includes side-channel-based techniques for bypassing kernel-level defenses, such as heap KASLR and MTE. One of my side-channel works, KernelSnitch, was nominated for a Pwnie Award in 2025. I have presented my research at several academic and industry conferences, including USENIX Security, NDSS, Black Hat USA, Black Hat Asia, and Nullcon Berlin.

The Last Proof of Human Craft: Forging a Microsoft Edge Full Chain with Logic Bugs Only!

Abstract

In the age of AI,

… finding renderer bugs with LLMs? Easy!
… turning them into a working RCE exploit? Doable: just burn enough tokens.
… completing a full sandbox escape? Maybe Mythos or even stronger models could do that.

But where’s the fun in easy? Let’s go for a hardcore run instead: crafting a browser full chain without any memory corruption bugs and, to make the game even harder, choosing not to use AI at all — sounds crazy, right?

Actually, building a full chain in the Chromium ecosystem isn’t as hard as you’d think if you use the right approach. In this talk, I’ll detail my logic-only chain against Microsoft Edge at Pwn2Own Berlin 2026. As the only browser pwned in the competition, and the first to escape Chromium’s sandbox at Pwn2Own since 2016, it earned $175,000 and helped secure the Master of Pwn trophy. All five bugs are chained together with pure logic: no renderer bugs, no memory corruption, no AI, and of course, no collisions at all!

Speakers

Orange Tsai

DEVCORE
@orange_8361

Bio

Orange Tsai is the principal security researcher at DEVCORE and a core member of CHROOT Security Group in Taiwan. He is also the champion and "Master of Pwn" title holder at Pwn2Own Vancouver 2021, Toronto 2022, and Berlin 2026, as well as a PHRACK #72 author. Over the years, Orange has spoken at several top hacking conferences such as Black Hat USA (6 times), DEF CON (5 times), HITCON (14 times), CODE BLUE (6 times), RomHack (2 times), Hexacon, POC, HITB, and WooYun!

Orange is a 0day researcher focusing on Web & App Security. His research not only earned him the Pwnie Award for "Best Server-Side Bug" in 2019 and 2021, and "Epic Achievement" in 2026, but also secured 1st place in the "Top 10 Web Hacking Techniques" for 2017, 2018, and 2024.

You can find me at @orange_8361 and https://blog.orange.tw/

MTEscape: Bypassing ARM's Asynchronous MTE with General Memory Corruption Vulnerabilities

Abstract

ARM Memory Tagging Extension (MTE) makes memory corruption vulnerabilities harder to exploit by detecting invalid memory accesses at runtime. To reduce performance overhead, MTE’s asynchronous mode defers tag-fault handling, leaving a brief window before the kernel responds. Can an attacker exploit that window?

In this talk, we present MTEscape, a technique that turns this narrow window into a practical exploitation opportunity in the Linux kernel. We show that both OOB write and UAF vulnerabilities can, under the right conditions, be used to interfere with MTE’s fault-handling mechanism before a pending violation is handled.

To make exploitation reliable, we must win a challenging single-attempt race. We will discuss the distinct strategies we developed for each vulnerability type and why they work despite the limited timing window.

Finally, we will walk through two real-world Linux kernel vulnerabilities to show how MTEscape can be applied in practice.

Speakers

Kyeongmin Kim

KAIST Hacking Lab
@hareh4ru

Bio

Kyeongmin Kim is an offensive security researcher at the KAIST Hacking Lab, where he focuses on advanced exploit techniques, automated vulnerability detection and exploitation. He is a multiple-time finalist in DEF CON, HITCON, and CODEGATE CTF competitions, including 2nd place at DEF CON 34. He was named a 2026 Microsoft Most Valuable Researcher (MVR) for his Windows vulnerability research. He studied at Korea University and is currently pursuing a master’s degree at KAIST.

Insu Yun

Associate Professor at KAIST

Bio

Insu Yun is an associate professor (untenured) at KAIST, currently leading Hacking Lab. He is interested in system security in general, especially binary analysis, automatic vulnerability detection, and automatic exploit generation. His work has been published at major computer security conferences such as IEEE Security & Privacy, USENIX Security, and USENIX OSDI. In particular, his research won Best Paper Awards at USENIX Security and OSDI in 2018, and he also won DARPA AIxCC with Team Atlanta.

In addition to research, he has participated in several hacking competitions as a security expert. In particular, he won Pwn2Own 2020 by compromising Apple Safari and won DEF CON CTF in 2015 and 2018.

Prior to joining KAIST, he received his Ph.D. in Computer Science from Georgia Tech in 2020.

One Parser, Two Bugs, Many Routers: Exploiting Broadcom WiFi Across eCos and Linux

Abstract

Broadcom wireless components have survived multiple operating systems, architectures, chipset generations, and product families. So have some of their security assumptions.

This talk follows the investigation of two previously undocumented vulnerabilities in Broadcom’s 802.11 implementation, beginning with legacy eCos-based cable gateways and extending to newer Linux-based platforms. Using a combination of manual reverse engineering and agent-assisted vulnerability research, we traced implementation lineage across firmware generations, reconstructed the wireless control plane, and identified remotely reachable flaws shared across multiple Broadcom SDK branches.

The vulnerabilities can be reached from 802.11 radio range without knowledge of the network key or completion of a normal WPS enrollment. Exploitation provides controlled information disclosure and arbitrary code execution, with the underlying behavior confirmed across ARM and MIPS firmware and multiple downstream products.

We will cover the complete research process: transferring knowledge from old targets to new ones, using agents to accelerate firmware analysis, developing reliable exploitation primitives, resolving runtime information through protocol responses, and dealing with the practical constraints of exploitation over lossy 802.11 traffic.

The talk also examines how shared SDK components propagate from chipset vendors to OEMs, ISPs, and end users, creating a gap between fixing a vulnerability and actually removing it from deployed devices. It concludes with the release of passive fingerprinting and verification tools intended to help researchers and operators identify potentially affected systems.

Speakers

Quentin Kaiser

@qkaiser

Bio

Quentin Kaiser (@qkaiser) is a former penetration tester turned binary analysis nerd. He is currently the Lead Security Researcher at ONEKEY, where he focuses on binary exploitation of embedded devices and large-scale bug-finding automation across firmware corpora.

He has published extensive research on offensive security for eCos and maintains https://ecos.wtf, a resource hub dedicated to eCos exploitation. He also (infrequently) updates his blog at https://quentinkaiser.be.

Parcel Security in Android: From Mismatch to Use-After-Free

Abstract

Parcel is a fundamental component of Android OS. It’s the core serialization mechanism for the majority of inter-process communication (IPC) between apps and OS. For years, malware and in-the-wild exploits have targeted Parcel vulnerabilities. In response, the Android Security team has dedicated tremendous effort to hardening the Parcel APIs.

At Black Hat EU 2022, we announced significant security enhancements in Android 13 designed to transform exploitable Parcel mismatch vulnerabilities into non-exploitable programming errors. Now, four years later, we are providing an update on the effectiveness of those hardening mechanisms. We’ll celebrate our successes, but also share an unexpected turn in our journey.

A bug fix intended to resolve a temporary file descriptor leak inadvertently introduced a critical Parcel Use-After-Free (UAF) vulnerability. This flaw allowed a LazyValue object to retain a dangling reference to a Parcel object after it had been recycled.

In this talk, we explore the challenges of securing Parcel APIs alongside the complexity and brilliance of three UAF exploits reported via the Android Vulnerability Rewards Program (CVE-2022-20452, CVE-2025-22429, and CVE-2025-48583). These exploits show how an attacker can steal sensitive Binder tokens and achieve arbitrary code execution. We’ll share the lessons we learned, the mitigations we implemented, and our plans for future work.

Speakers

Yang Kudurshian

Google

Bio

Yang is a security researcher who enjoys tackling complex technical challenges, dissecting novel vulnerabilities and exploitation techniques, and building defenses that eliminate exploit primitives at the root. At Google, she leads Android vulnerability research and mitigation, focusing on the framework and userspace.

John Wu

Google
@topjohnwu

Bio

John Wu (@topjohnwu) is a software engineer and prominent open-source developer, best known as the creator of Magisk, the popular rooting framework for Android.
At Google, he previously served as a tech lead on the Android Platform Security team. He currently leads efforts on building a host-side testing platform designed to run native Android tests efficiently without the overhead of virtual machines or emulators.

Reinventing the vPhone — A Next-Generation iOS Security Research Platform

Abstract

Apple and commercial offensive security companies have relied on iOS virtualisation for years while keeping their implementation details proprietary. In 2026, Apple unexpectedly shipped firmware for one of its internal virtual devices, the vphone600, enabling the community to build the first open-source iOS 26 virtualisation environment. This marked a major shift from previous QEMU-based efforts and opened entirely new opportunities for vulnerability research, exploit development, and dynamic spyware analysis.

We will present our work on transforming the open-source vPhone ecosystem from a heavily patched research prototype into a significantly more realistic offensive research platform. By recreating Apple’s firmware generation pipeline, we generate accepted filesystem artifacts instead of bypassing integrity checks, allowing the virtual device to boot while preserving core security mitigations. This enables security research in an environment that more closely resembles real-world devices.

Speakers

Maximilian Paß

Hasso Plattner Institute

Bio

Maximilian Paß is a master's student in the research group for Mobile and Wireless Security at Hasso Plattner Institute (HPI), Potsdam. His research focuses on mobile surveillance technologies, state-sponsored spyware, and the security analysis of mobile platforms.

Revisiting SecureROM Adventures

Abstract

In June 2026, Paradigm Shift published usbliter8, a reminder that the SecureROM still holds surprises! A DMA bug in the Synopsys DesignWare (DWC2) USB controller that Apple has relied on for years. This talk returns to that attack surface through a different lens, and a variant of the same bug.

We begin with a brief tour of Apple’s Secure Boot ecosystem, where trust is anchored, and where a flaw in silicon is one that stays with the device. From there, the core of the talk: the effort to exploit this bug generically and across a decade of Apple SoCs, from A5 to A13. It is the story of an exploit that never quite stayed finished, rebuilt repeatedly as SecureROM and iBoot hardened over successive generations. Some techniques carried across many SoCs; others stopped working entirely on modern ROMs.

Along the way, we encountered something we still cannot fully explain: strange, undocumented behaviour of the SoC itself, doing something it was never meant to. We don’t yet know why it exists… Only that it made exploitation dramatically easier. We’ll also cover how we turned a temperamental USB attack into a reliable one.

We close where the story ends: the point at which modern Apple silicon shuts this surface down, and how far the secure-boot ecosystem has moved from the devices we set out to explore.

Speakers

Steven De Franco

Cellebrite
@iH8sn0w

Bio

Canadian security researcher specializing in Apple platforms since the iPhone OS 3.x / iPod touch 2 era. Once part of the iOS jailbreak scene, my work revolves around security-critical components including iBoot/SecureROM, Secure Enclave, Boot Monitors, and Lynx/Ocelot.

Wasm Spills The Beans on Chrome and Safari

Abstract

Browsers are complex pieces of software and throughout the years they have been a prime target for vulnerability researchers.
Complexities arise when browsers implement standards and functionality to make the web experience better for the user. It is in that intersection where this talk develops: The implementation of WebAssembly and the optimizations on the code produced by the WebAssembly implementation.
WebAssembly is affected by the JIT compilation and optimization pipelines. Amongst those, we can find register allocation routines that try to make efficient use of registers.
This talk shows how in both V8, the JavaScript Engine of Chrome, and JavaScriptCore, the JavaScript engine for Safari, a very similar type of bug arised.
Covering how this bug was found via fuzzing and how collissions not only happen in bugs but in “fuzzing ideas” with other researchers. We’ll then focus on this somewhat less known family of register allocator bugs; showing how, due to the evolution of the WebAssembly standard standard and implementation by the Browser vendors, one resulted in just an info-leak and the later case
fully exploitable, turning a type confusion into renderer code execution.

Speakers

Javier Jimenez

CYONYX
@n30m1nd

Bio

Focusing on all things browser vulnerability research, fuzzing and LLM post-training.

When Picos Attack – USB Exploit Engineering

Abstract

Over the last year research has been performed into practical USB exploitation by NCC’s exploit development group. Whilst there have been previous investigations into finding USB memory corruption-based vulnerabilities, there is much more limited public domain information on exploitation.

In 2025, Amnesty International released the first detailed write-up of an in-the-wild chain of USB related vulnerabilities which was used to compromise mobile phones demonstrating that these attacks are a real threat.

This left us with the question - “just how practical are USB memory corruption vulnerabilities to exploit against modern operating systems and what constraints are there?”

In the process we developed a framework which we call Dynamic USB Exploitation Tool (D.U.E.T.). The framework allows us to rapidly prototype new USB devices, perform common exploit techniques (such as heap manipulation) and transmit data in both directions between the USB device and the attacker (to allow for controlled information leakages and KASLR bypasses).

This framework was implemented on top of Raspberry Pi Pico’s as a related inexpensive way to deploy and coordinate large numbers of custom USB exploitation devices of varying exploitation roles via Wi-Fi.

Whilst performing this research and development, we discovered issues which affected Tesla’s automotive in-vehicle infotainment (IVI), core Linux kernel components, and developed several exploits along the way (CVE-2024-53150, CVE-2024-53104).

This talk will start by walking viewers through the Linux kernel attack surface of USB, discussing in-the-wild vulnerabilities, describing exploitation of three vulnerabilities and then moving on to discussion of the framework we developed.

Finally, we will wrap the talk up by demonstrating an end-to-end exploit for a modern Ubuntu version.

Speakers

Alex Plaskett

NCC Group
@alexjplaskett

Bio

Alex Plaskett (@alexjplaskett) is an Associate Director within the Exploit Development Group (EDG) at NCC Group. Alex is a five-time Pwn2Own winner (desktop, mobile, embedded, and automotive) and has over 20 years of experience in vulnerability research and exploitation. Alex has exploited vulnerabilities in a large range of high-profile products across many different areas of security. Alex is a frequent speaker at security conferences (e.g. BlackHat, OffensiveCon, Hexacon, HITB, BlueHat, POC, Troopers etc). Alex was previously leading security teams in Fintech, Mobile Security and Security Research) and just generally causing vendors to patch things on a regular basis!