Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2023-21674] Chaining N-days to Compromise All: Part 2 — Windows Kernel LPE (a.k.a Chrome Sandbox Escape)

Summary

Part two of the chain: how CVE-2023-21674, a use-after-free in the Windows NT kernel involving ALPC, was exploited to escape the Chrome sandbox — the year’s first in-the-wild kernel bug.
Published
Collected

original ↗

Related coverage

back