logo

RedpwnCTF 2021 Chromium SBX Tasks Writeup (Empires and Deserts)

ID: 5d762e35-1a48-54aa-99be-22984c74edac

STIX ID: report--5d762e35-1a48-54aa-99be-22984c74edac

Feed Name: Will's Root

Threat Score
60/100

Date Published: 2021-07-13

Date Updated: 2026-04-19

Author: Unknown

...
...

This report is a CTF writeup describing a Chromium sandbox-escape vulnerability in Mojo-serialised structs that allows OOB/uninitialized reads and leaking of an UnguessableToken to trigger a backdoor mapping RWX memory and execute shellcode; the author explains the buggy structs, exploitation strategy, mojojs binding changes, and demonstrates a working exploit in the challenge environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.