Intro to Chrome’s V8 from an exploit development angle
ID: fe4823ee-8268-5ccc-a7b4-e36f20727b36
STIX ID: report--fe4823ee-8268-5ccc-a7b4-e36f20727b36
Feed Name: SensePost Blog
This blog post walks through V8 internals—Ignition, TurboFan, and the Turbolizer tool—showing how JIT speculative optimizations can lead to type-confusion and bounds-check elimination exploits. It includes example code, d8 trace flags, Turbolizer visualizations, and a gdb debugging session, and notes recent V8 hardenings that mitigate the demonstrated bounds-check removal vectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
