WOOT aims to present a broad picture of offense and its contributions, bringing together researchers and practitioners in all areas of computer security
Our @wootsecurity'26 paper "CATana" is now available: usenix.org/system/files/w…!
In the paper, we find that some phones and many IoT devices execute AT commands sent by the SIM, leading to a wide range of consequences from DoS over 2G downgrade to device compromise.
Android's ART caches C++ mirror objects for app-specific Java classes/methods. That file is typically stored in the app’s private directory, writable by the app itself at runtime. Pretty sure there is nothing that can go wrong with that! usenix.org/conference/woo…
GRAPE is cross-context code-pattern scanner that scans the entire Chromium code base in 12 minutes and earned the Authors of "Squeezing Juicy Variant Bugs Out of Modern Browsers" $17k5 for 24 newly-found vulnerabilities.
Pre-print: kdsjzh.github.io/assets/pdf/26W…