RedpwnCTF 2021 Chromium SBX Tasks Writeup (Empires and Deserts)
ID: 5d762e35-1a48-54aa-99be-22984c74edac
STIX ID: report--5d762e35-1a48-54aa-99be-22984c74edac
Feed Name: Will's Root
Threat Score
This report is a CTF writeup describing a Chromium sandbox-escape vulnerability in Mojo-serialised structs that allows OOB/uninitialized reads and leaking of an UnguessableToken to trigger a backdoor mapping RWX memory and execute shellcode; the author explains the buggy structs, exploitation strategy, mojojs binding changes, and demonstrates a working exploit in the challenge environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
