Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Natalie Silvanovich

@natashenka@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Tamagotchi hacker. Google Project Zero. she/her

1133 Followers
129 Following
32 Posts
Joined December 14, 2022
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 1mo ago

Project Zero is hiring!

https://goo.gle/3UMXQIZ

Please share with anyone you think would be great for the role.

goo.gle
23
1
30
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 1mo ago

Weekend project

10
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 1mo ago

For all the uncertainty they cause, LLMs are pretty terrible at creating slides of question marks doing the conga

7
0
2
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago

The passage of time is relentless

12
0
2
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago

What if Python smelled the flowers? Read a book? Did anything but complain about consistent use of tabs and spaces?

16
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 4mo ago

Seth Jenkins updated our 0-click exploit chain to work on a Pixel 10 with an eye-popping driver bug!

We’ll be presenting this work Saturday @offensive_con@bird.makeup

https://projectzero.google/2026/05/pixel-10-exploit.html

projectzero.google
32
0
8
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago

You are the manager of a vulnerability research team. You are easily distracted and often late for meetings. You forget important emails.

8
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 3mo ago
New variation on an old theme: reporting a low severity bug because AI *fixates* on it to the exclusion of other bugs
11
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Remarkably, iOS also integrates the UDC in a 1-click context, but this bug is not exploitable, because the codec is compiled with -fbounds-safety, which inserted bounds checking instructions, making the bug unreachable.
47
3
19
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago
When you join the Stonecutters, you get the real H264 conformance test vectors, that really test all the features
4
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
The first bug in the chain is CVE-2025-54957, a memory corruption bug in the Dolby Unified Decoder, an audio codec integrated by most Android devices’ OEMs. It is 0-click because incoming SMS and RCS audio messages are automatically transcribed by the system.
34
14
14
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 3mo ago

Some of us don’t snitch, alright?

https://www.calparks.org/press/californians-urged-observe-and-report-monarch-butterfly-sightings

calparks.org
7
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 5mo ago

Big changes to Android and Chrome VRP:

- focus on high-impact, reproducible bugs with low/no reward for lower impact
- big prizes for full chains with some annual limits
- PoCs required

It’s the end of an era, but the start of a new one.

https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era

bughunters.google.com
13
0
8
1
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
IMO, the biggest takeaway from this research is the huge promise shown by memory mitigations, both hardware and software, in protecting users against 0-days.
20
1
9
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 7mo ago

Ivan Fratric shares some tips and tricks for grammar fuzzing

https://projectzero.google/2026/03/mutational-grammar-fuzzing.html

projectzero.google
13
1
9
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 6mo ago

Just put a reminder in my calendar for November 1, 2026 to check whether we still have bugs

10
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
IMO, the biggest takeaway from this research is the huge promise shown by memory mitigations, both hardware and software, in protecting users against 0-days.
17
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 4mo ago

And the Owl said, “If you want to find the maintainer, go to the north side of the pond when the moon is out. Turn yourself around three times, then look into the water to see them.”

5
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago

Our intrepid 20%-er @dillonfranke@infosec.exchange exploited a vulnerability in CoreAudio. See his process for gaining privilege escalation on a Mac:

https://projectzero.google/2026/01/sound-barrier-2.html

projectzero.google
14
0
7
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
The second bug, CVE-2025-36934, is a driver UaF which only affects the Pixel 9, but Project Zero has found many other bugs with similar impact affecting other devices over the past couple years.
14
1
4
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Make sure to check out the full series here: https://projectzero.google/2026/01/pixel-0-click-part-1.html
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
projectzero.google

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Over the past few years, several AI-powered features have been added to mobile phones that allow ...

13
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 7mo ago
9
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Attack surface reduction is also important— the UDC is largely used by commercial media like TV shows, most devices don’t even have an encoder. Does it really need to be 0-click?
12
3
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Supply-chain issues also played a role: both vulnerabilities were patched very slowly, due to a variety of factors including bug prioritization, licensing and communication between vendors.
9
1
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 5mo ago

Amazing work by Meta implementing fast and robust WebRTC updates!

“We can’t push updates because …” can often be solved with investment and innovative engineering

https://engineering.fb.com/2026/04/09/developer-tools/escaping-the-fork-how-meta-modernized-webrtc-across-50-use-cases/

Escaping the Fork: How Meta Modernized WebRTC Across 50+ Use Cases
Engineering at Meta

Escaping the Fork: How Meta Modernized WebRTC Across 50+ Use Cases

At Meta, WebRTC powers real-time audio and video across various platforms. But forking a large open-source project like WebRTC within our monorepo presents unique challenges – over time, an interna…

4
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 4mo ago

There’s ‘shrinkwrap’ on this Tamagotchi … sticker

2
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 5mo ago

There’s a little piece of my heart that beats just for Spanify

https://groups.google.com/a/chromium.org/g/chromium-dev/c/iEy69ygz-rs

groups.google.com
2
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 14mo ago
Replying to
(🔥🔥🔥)
1
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago
I’ve been Palling and Malling for so long that even my Momma thinks that my mind is gone
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 00:25:25 UTC