Using Kerberos for Authentication Relay Attacks

Simple Linux kernel memory corruption bug leads to complete system compromise

Fuzzing Closed-Source JavaScript Engines with Coverage Feedback

Understanding Network Access in Windows AppContainers

An EPYC escape: Case-study of a KVM breakout

Fuzzing iOS code on macOS at native speed

Designing sockfuzzer, a network syscall fuzzer for XNU

Policy and Disclosure: 2021 Edition

A Look at iMessage in iOS 14

The State of State Machines

The In-the-Wild Series

An iOS hacker tries Android

An iOS zero-click radio proximity exploit odyssey

Oops, I missed it again

Enter the Vault: Authentication Issues in HashiCorp Vault

Attacking the Qualcomm Adreno GPU

JITSploitation I: A JIT Bug

Project Zero Released a Zero-Click Exploit for Signal

MMS Exploit Part 5: Defeating Android ASLR, Getting RCE

One Byte to rule them all

How to unc0ver a 0-day in 4 hours or less

Detection Deficit: A Year in Review of 0-days Used In-The-Wild in 2019

A survey of recent iOS kernel exploits

FF Sandbox Escape (CVE-2020-12388)

Fuzzing ImageIO

You Won't Believe What This One Line Change Did to the Chrome Sandbox

What a one line change did to the Chrome sandbox

Mitigations are attack surface, too

Escaping the Chrome Sandbox with RIDL

Several months in the life of Project Zero – Part 1: The Chrome bug of suffering

More →