-
-
Revisiting ReDoS Attacks
Again! Watch your regexes!
By m411k, Ayoub, 0xMokhtari -
Exploiting Chromium 140 Renderer Process
CVE-2025-10891 RCE PoC
By m411kPostscriptum: OtterSec have since exploited this same bug on mobile renderers more elegantly (no spraying, no stack pivot: bytecode-smuggled constants reach DeserializeWasmModule with a shellcode-packed Wasm module), and it works on ARM too, where PAC/BTI and the 16-byte SP alignment requirement make stack pivoting painful. [Read More]