Announcements
Alisa Esage
Owner of Zero Day Engineering
0-Day Insights
Google Chrome "actively exploited" bug chain on Viz & v8-wasm (May 2024)
Root cause analysis of a two-bug Chrome exploit chain under active exploitation in May 2024: CVE-2024-4671 (sandbox escape via Use-after-free in Viz) and CVE-2024-4761 (remote code execution via v8-wasm type confusion).
0-Day Insights
VMware Critical Security Advisory for ESXi, Workstation, Fusion hypervisors
1. Vmware just released security patches for four critical vulnerabilities that affect their entire core hypervisor stack: CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255. 2. The bugs were publicly…
0-Day Insights
Google Chrome WebRTC 0-Day Vulnerability (CVE-2023-7024)
WebRTC is a universal open source codec library for processing audio and video streaming, which is embedded in a wide variety of software products, especially in web browsers. Google justdiscloseda zero-day vulnerability in WebRTC, which is being exploited in the wild to achieve…
0-Day Insights
Deep Dive: Qualcomm MSM Linux Kernel & ARM Mali GPU 0-day Exploit Attacks of October 2023
This deep technical note briefly covers five kernel vulnerabilities in Qualcomm chipsets & ARM Mali GPU, which landed on CISA Known Exploited Vulnerabilities Catalog between October and December 2023. All the bugs were reported to be exploited "in…
0-Day Insights
Google Chrome Skia Vulnerability Analysis (CVE-2023-6345)
Google recently disclosed a new zero day vulnerability in Chrome browser that was exploited to attack users "in the wild". The bug is said to affect Skia component and tracked as CVE-2023-6345, with a CVSS score of 9.6 (Critical). No technical details of the vulnerability or…