-
Notifications
You must be signed in to change notification settings - Fork 116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
not exactly an issue but a suggestion: study (and possibly port) CVE 2020-9951 #55
Comments
I will take a look into it; at least it does not like an obvious dead end, like any JIT-based exploit. Will have to build a debug version of the whole WebKit though; my current script only builds JavaScriptCore. |
thanks. i hope there is a solution here :) |
since i also don't know your twitter handle or handle for other social media i'll leave this here https://www.sendspace.com/file/sg19ns |
I do have Twitter, however I registered one specifically to reach Al Azif and don't really check it. As of now Telegram is my primary messenger. Thanks anyway, will check this out as soon as I reach my PC. |
Sergey, did you had the chance to give it a look? |
It seems that I have a PoC, but nowhere close to a working exploit yet. |
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1155 |
Hey. the webkit 0day was introduced today, which should theoretically work on 7.xx. you are the developer who can implement it on this firmware. do you have time to try adapting this for 7.xx? |
I already saw this, but thanks anyway. |
Here's a list of CVE that may be useful. I'm a fan of your talent 👍 |
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1124
Seems like a good candidate. What better person to port this than a russian? Of course we need to check if ps4 webkit is vulnerable to this, but if it is we should have a proper webkit exploit for 7.02 and below (and who knows, 7.55 and below as well?)
The text was updated successfully, but these errors were encountered: