-
-
Revisiting ReDoS Attacks
Again! Watch your regexes!
By m411k, Ayoub, 0xMokhtari -
Exploiting Chromium 140 Renderer Process
CVE-2025-10891 RCE PoC
By m411kPostscriptum: OtterSec have since exploited this same bug on mobile renderers more elegantly (no stack pivot: bytecode-smuggled constants reach DeserializeWasmModule with a shellcode-packed Wasm module), and that’s on ARM, where the 16-byte SP alignment requirement made stack pivoting painful for me. [Read More]