Free courses from frontend to fullstack and AI
Learn Excel and Financial Modeling the Way Finance Teams Actually Use Them
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This presentation introduces ANGLE and its role in browser WebGL/WebGL2, then analyzes exploitable Chromium and Safari vulnerabilities. It demonstrates exploitation steps leading to macOS remote code execution, without covering the iOS PAC bypass.
Syllabus
Intro
Background of ANGLE
ANGLE Architecture Overview
WebGL Implementation
Chrome texStorage3D Out of Bound Read
Safari MultiDrawArrays Heap overflow
Safari Transform Feedback Use After Free
Allocate Buffer Object
Exploitation Steps
JSC's Butterfly Overview
Step 1: Heap Spray
Trigger the Bug
Search Corrupted JSArray
Get JSCell and Structure ID
Get addrof/fakeobj primitives
Taught by
Hack In The Box Security Conference