Live data from Hacker News

GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years

nebusec.ai

1–10 of 209 posts

Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years

#9

>Google has rewarded us $92,337 in kernelCTF I'm all ears now

Seems low considering the wide impact, but maybe the only thing corporations throw big money at is remote exploits?

That's a huge amount of money for a vulnerability.

Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years

#10
Tested on three Android devices (version 9, 13, 16) with different Firefox versions under 150 (had to modify for older).

Two boot looped, I had to enter recovery and the other just powered off [0].

The demo modifies the wallpaper on supported Pixel devices.

[0] IonStack https://rootme.nebusec.ai

____

Tip: Install a Chromium flavor browser (Chromite) separate from the main browser.

Disable Javascript and hardware accelerated video decoder (commonly exploited) from the flags page and enable reader mode to fix broken JS-dependent websites when browsing blogs and random sites on your personal devices, else dedicate a tablet.

Post reply on HN