logo

Google Project Zero

ID: 3fef7083-300f-5beb-88de-4326f14e512d

STIX ID: identity--3fef7083-300f-5beb-88de-4326f14e512d

Feed Type: atom

Earliest post: 2022-03-31

Latest post: 2025-12-12

Technical write-ups and vulnerability research from Google’s offensive security team focused on finding zero-day exploits in the wild.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
A look at an Android ITW DNG exploit2025-12-12TrueGoogle Project ZeroTrue
Defeating KASLR by Doing Nothing at All2025-11-03TrueGoogle Project ZeroTrue
Pointer leaks through pointer-keyed data structures2025-09-26TrueGoogle Project ZeroTrue
From Chrome renderer code exec to kernel with MSG_OOB2025-08-08TrueGoogle Project ZeroTrue
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages2025-05-09TrueGoogle Project ZeroTrue
Blasting Past Webp2025-03-26TrueGoogle Project ZeroTrue
Windows Bug Class: Accessing Trapped COM Objects with IDispatch2025-01-30TrueGoogle Project ZeroTrue
Simple macOS kernel extension fuzzing in userspace with IDA and TinyInst2024-11-21TrueGoogle Project ZeroTrue
From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code2024-11-01TrueGoogle Project ZeroTrue
Effective Fuzzing: A Dav1d Case Study2024-10-03TrueUnknownTrue
Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models2024-06-20TrueGoogle Project ZeroTrue
Driving forward in Android drivers2024-06-13TrueGoogle Project ZeroTrue
The Windows Registry Adventure #1: Introduction and research results2024-04-18TrueGoogle Project ZeroTrue
Analyzing a Modern In-the-wild Android Exploit2023-09-19TrueGoogle Project ZeroTrue
MTE As Implemented, Part 1: Implementation Testing2023-08-02TrueGoogle Project ZeroTrue
MTE As Implemented, Part 3: The Kernel2023-08-02TrueGoogle Project ZeroTrue
Release of a Technical Report into Intel Trust Domain Extensions2023-04-24TrueGoogle Project ZeroTrue
Multiple Internet to Baseband Remote Code Execution Vulnerabilities in Exynos Modems2023-03-16TrueGoogle Project ZeroTrue
Exploiting null-dereferences in the Linux kernel2023-01-19TrueGoogle Project ZeroTrue
DER Entitlements: The (Brief) Return of the Psychic Paper2023-01-12TrueGoogle Project ZeroTrue
Exploiting CVE-2022-42703 - Bringing back the stack attack2022-12-08TrueGoogle Project ZeroTrue
Mind the Gap2022-11-22TrueGoogle Project ZeroTrue
A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain2022-11-04TrueGoogle Project ZeroTrue
Gregor Samsa: Exploiting Java's XML Signature Verification2022-11-02TrueGoogle Project ZeroTrue
RC4 Is Still Considered Harmful2022-10-27TrueUnknownTrue
The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I)2022-08-10TrueGoogle Project ZeroTrue
2022 0-day In-the-Wild Exploitation…so far2022-06-30TrueGoogle Project ZeroTrue
The curious tale of a fake Carrier.app2022-06-23TrueGoogle Project ZeroTrue
An Autopsy on a Zombie In-the-Wild 0-day2022-06-14TrueGoogle Project ZeroTrue
Release of Technical Report into the AMD Security Processor2022-05-10TrueRyanTrue
The More You Know, The More You Know You Don’t Know2022-04-19TrueRyanTrue
CVE-2021-1782, an iOS in-the-wild vulnerability in vouchers2022-04-14TrueRyanTrue
CVE-2021-30737, @xerub's 2021 iOS ASN.1 Vulnerability2022-04-07TrueRyanTrue
FORCEDENTRY: Sandbox Escape2022-03-31TrueRyanTrue

1–34 of 34