The Hat Trick: Exploit Chrome Twice from Runtime to JIT
Автор: Black Hat
Загружено: 2023-12-19
Просмотров: 1736
Описание:
With updates to the JS standard and requirements for higher runtime efficiency, Google's JS engine V8 has implemented newer features such as built-in functions like Promise.any and the Maglev mid-tier compiler.
Maglev is a compilation optimization layer in V8 that is situated between Sparkplug and Turbofan in order to accelerate the optimization and compilation of JS code. However, due to the involvement of compilation and optimization-related mechanisms in the Maglev compilation layer, deep and complex code logic can hide undetected security vulnerabilities....
By: Nan Wang , Zhenghang Xiao
Full Abstract and Presentation Materials: https://www.blackhat.com/us-23/briefi...
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: