
X Site eScape (Part II): Look Up a Shell in the Dictionary
A funny bug chain turing inter-process XSS to native code execution for sandbox escape.

A funny bug chain turing inter-process XSS to native code execution for sandbox escape.

A funny bug chain turing inter-process XSS to native code execution for sandbox escape.

Copycat.

Copycat.

Triggering inter-process XSS for fun and profit.

Triggering inter-process XSS for fun and profit.

Useless bugs are just being given up too early.

Useless bugs are just being given up too early.

Similar to DLL sideloading, legit plugins on macOS could be abused to load executable code on startup.

Similar to DLL sideloading, legit plugins on macOS could be abused to load executable code on startup.

Relying on pid to validate IPC peer is unsafe.

Relying on pid to validate IPC peer is unsafe.