A Deep Dive into V8 Sandbox Escape Technique Used in In-The-Wild Exploit
Summary
How Theori escaped the V8 sandbox by abusing a raw pointer in the WasmIndirectFunctionTable object to gain arbitrary write and code execution, plus patch analysis of related sandboxification commits.
- Published
- Collected
Skip to content