logo

Turboflan PicoCTF 2021 Writeup (v8 + introductory turbofan pwnable)

ID: 055f7a70-127f-51c7-99ab-216325f52112

STIX ID: report--055f7a70-127f-51c7-99ab-216325f52112

Feed Name: Will's Root

Threat Score
30/100

Date Published: 2021-04-06

Date Updated: 2026-04-19

Author: Unknown

...
...

This is a technical exploit writeup for a Turbofan JIT bug in V8 (Chromium) used in picoCTF 2021: the author demonstrates a removed deopt check causing type confusion between double and packed object arrays, builds addrof/fakeobj and arbitrary read/write primitives, and uses a wasm RWX page to run shellcode. The writeup is a CTF/d8 proof-of-concept with environmental restrictions (d8 only, no real Chrome remote, firewall limits) and does not present evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.