Last week I did a livestreamed talk on browser security. In case you missed it and are interested, here are the slides: saelo.github.io/presentations/…
And the recording: youtu.be/maWnIKH3JQI?si…
Thanks @calif_io for hosting and the audience for listening and asking questions! :)
youtube.com/live/yk1G5uL3c…
Alright, let's try this livestream thing again. Hopefully it will work this time.
We spent some time hacking browsers and wanted to understand what the future of exploitation may look like in this field. So we decided to invite the GOAT of browser
youtube.com/live/iZE_iHcv7…
Our researchers spent several weeks developing a full Chrome exploit chain and wondered about the current state-of-the-art in this area.
For the benefit of the community, we invited the GOAT of browser exploitation, @5aelo, to share his perspectives on
* Seems many exploits couldn't be demoed due to bad luck/last-minute fixes. Really sorry for the participants :( great research!
* No V8 (and Chrome?) submissions for the 2nd year in a row
* @orange_8361's chain sounds wild, very curious for details!
Thanks for #Pwn2Own@thezdi
We have received 6 browser entries for #Pwn2Own Berlin 2026:
* Mozilla Firefox renderer: 3
* Apple Safari renderer: 2
* Microsoft Edge renderer + Sandbox escape: 1