the grugq's newsletter

Subscribe
Archives
March 19, 2024

March 19, 2024

March 19, 2024

In this post I'll use CVE-2023-6241, a vulnerability in the Arm Mali GPU that I reported last November to gain arbitrary kernel code execution from an untrusted app on a Pixel 8 with MTE enabled. https://t.co/Flsas2jJtv

— Man Yue Mo (@mmolgtm) March 18, 2024

Gaining kernel code execution on an MTE-enabled Pixel 8 - The GitHub Blog

In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulnerability can be exploited even when Memory Tagging Extension (MTE), a powerful mitigation, is enabled on the device.


A twitter front end, I think running Nitter? Maybe useful to some people.

wint @dril , Twitter Profile - twstalker.com

Twstalker, Search twitter profiles and analyze trending topic hashtags.


Excellent overview of glibc heap exploitation techniques by @0xricksanchezhttps://t.co/W68gcn9fAR#glibc #cybersecurity pic.twitter.com/oqTprx2q9K

— 0xor0ne (@0xor0ne) March 19, 2024


It gets worse. Apparently if you search "as of my last knowledge update" or "i don't have access to real-time data" on Google Scholar, tons of AI generated papers pop up. This is truly the worst timeline. pic.twitter.com/YXZziarUSm

— Life After My Ph.D. (@LifeAfterMyPhD) March 18, 2024


Black Cat at Night, Shoda Koho, 1920–1929. Woodblock print. https://t.co/8RHYPyIKIW pic.twitter.com/rSRRFwlAY2

— Cats in Art (@CatsinArt1) March 17, 2024


The most critical risk to society in cybersecurity is the floor, not the ceiling. Good cybersecurity is too expensive, so the largest tech companies can succeed, but your hospitals, food distribution networks, and power plants generally cannot. That's the problem to be solved.

— Dino A. Dai Zovi (@dinodaizovi) March 17, 2024


Same as it ever was pic.twitter.com/il49Ny3JFd https://t.co/YuVoaynoJ2

— Dug Song (@dugsong) March 18, 2024

NEW: The U.S. government has yet to learn the full extent of a massive Chinese espionage campaign that targeted American critical infrastructure, according to a senior @NSAGov official.

On @TheRecord_Media https://t.co/6R2SVO3Y92

— Martin Matishak (@martinmatishak) March 18, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X