logo

Cascading Chaos: A GOT-Oriented Exploit Story

ID: 79d81c32-ed84-50c6-963d-aec733aef13a

STIX ID: report--79d81c32-ed84-50c6-963d-aec733aef13a

Feed Name: Claroty Team82

Threat Score
60/100

Date Published: 2025-07-25

Date Updated: 2026-04-17

Author: Tomer Goldschmidt

...
...

Team82 researcher Tomer Goldschmidt documents a novel exploitation technique that leverages a pre-authenticated format-string vulnerability on an end-of-life ARM-based device to obtain write-what-where primitives, perform partial GOT overwrites, and chain GOT modifications ("Cascading GOT Call Chain") to achieve remote code execution. The report includes an ARM32 QEMU emulation setup, compilation flags to mirror the target, step-by-step exploit development (including %n positional specifiers and byte-wise GOT overwrites), debugging artifacts, and a pwnlib-based PoC demonstrating a reverse shell.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.