Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Allison Husain

@ezhes_@mastodon.online
mastodon 4.7.0-nightly.2026-08-14
  • Open on mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

0 Followers
0 Following
7 Posts
Joined November 07, 2022
Blog:
https://ezh.es

Posts

Open post
ezhes_
Allison Husain @ezhes_@mastodon.online · Jul 08, 2026
Allison Husain
@ezhes_@mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

mastodon.online
Replying to @steve@discuss.systems
@steve@discuss.systems my favorite is that there's a bug somewhere in LLVM which causes lots of branches to PC+4 :/
0
1
0
0
Open post
ezhes_
Allison Husain @ezhes_@mastodon.online · Jun 10, 2026
Allison Husain
@ezhes_@mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

mastodon.online
Boosted by disregard Joe Groff @joe@f.duriansoftware.com
Replying to @joe@f.duriansoftware.com
@joe@f.duriansoftware.com compiler interns getting their first paycheck
1
0
2
0
Open post
ezhes_
Allison Husain @ezhes_@mastodon.online · Sep 09, 2025
Allison Husain
@ezhes_@mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

mastodon.online
Replying to @ezhes_@mastodon.online
/4 and, best of all, these same properties work identically to mitigate arb offset OOB Spectre v1 gadgets in a way which is performant enough to ship in a consumer product. This lets us defend MTE tags in the kernel against Spectre V1 by forcing attackers to deal with type isolation in order to leak the tags they need to further their memory corruption related attacks.
13
2
2
0
Open post
ezhes_
Allison Husain @ezhes_@mastodon.online · Sep 09, 2025
Allison Husain
@ezhes_@mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

mastodon.online
Replying to @ezhes_@mastodon.online
/3 For example, a first-order arb offset OOB write in a kalloc_type submap can now only target the per-boot random set of types on that same submap front, which can make exploiting what used to be one of the best flavors of bug quite hard. This is even more fun when considering the data submap where an arb write is now restricted to targeting only other data allocations. Any types (eg. pointers, indexes, etc.) you could target to escape the data heap are themselves patchable security bugs :)
13
1
2
0
Open post
ezhes_
Allison Husain @ezhes_@mastodon.online · Sep 09, 2025
Allison Husain
@ezhes_@mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

mastodon.online
Replying to @ezhes_@mastodon.online
/2 The trick behind this mitigation is to use the compiler to clamp all pointer offset operations in kernel code to a magnitude of less than 4GB. If you feel like grep-ing, the specific codegen for this clamp operation currently uses a special 0x2BAD poisoning pattern in the top 16 bits when the magnitude exceeds 4GB. With some VA layout tricks to inject large 4GB unmapped gutters between major kernel VA regions, this has some delightful consequences.
22
5
11
0
Open post
ezhes_
Allison Husain @ezhes_@mastodon.online · Sep 09, 2025
Allison Husain
@ezhes_@mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

mastodon.online

Memory Integrity Enforcement is the culmination of a truly incredible amount of work :)

While there's so much to love, one of my favorite pieces was getting to bring kalloc_type-style isolation to out-of-bounds accesses on both the architectural and speculative path. This lets us both mitigate a variety of Spectre v1 style attacks and break the reliable exploitation of some of the most powerful first-order memory corruption primitives (arb offset OOB R/W).

https://security.apple.com/blog/memory-integrity-enforcement/

167
4
97
0
Open post
ezhes_
Allison Husain @ezhes_@mastodon.online · Aug 10, 2025
Allison Husain
@ezhes_@mastodon.online

"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" 
she/her

mastodon.online
Replying to @ozzelot@mstdn.social
@ozzelot@mstdn.social @nclm@mastodon.social @sheepfilms@mastodon.social I have no idea if it's true, but I the literal interpretation (bus=>thing which moves stuff between fixed points) seems fairly reasonable to me given a data bus moves data between some number of points.
1
0
0
0

Remote instance

mastodon.online
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 09:52:22 UTC