clem1
@_clem1
Followers
7K
Following
9K
Media
3
Statuses
861
woah...Exploited ITW (CVE-2025-10585)[445380761][compiler][maglev]Type Confusion https://t.co/hDTfgo0aPt
https://t.co/g51IHemMKc
https://t.co/iphJnonX6e Reported by Google TAG
1
16
51
Weโre thrilled to announce Donncha ร Cearbhaill (@DonnchaC) as our keynote speaker for HEXACON 2025! ๐ฅ No doubt he has plenty of juicy stories up his sleeve ๐พ
0
8
36
If you've been keeping track on the Big Sleep bug tracker at https://t.co/TeYPpUANyW you might have noticed it lists more bugs now compared to last week. Including a "High impact issue in V8" :)
3
21
102
Exploited ITW (CVE-2025-6558)[427162086]Incorrect validation of untrusted input(transform feedback buffer modification) https://t.co/K7R3nSiQj9
https://t.co/DmvKa9nErk Reported by Clรฉment Lecigne(@_clem1) and Vlad Stolyarov(@vladhiewsha)
2
24
70
Leak hole PoC for Chrome in-the-wild vulnerability CVE-2025-6554 published yesterday: https://t.co/BYk7k8FAxL
5
55
183
After 6 months of responsible disclosure, proud to announce our team discovered 13 (mostly exploitable) vulnerabilities in Samsung Exynos processors! Kudos to @st424204, @n0psledbyte, @Peterpan980927 & @rainbowpigeon_ CVE-2025-23095 to CVE-2025-23107 ๐
semiconductor.samsung.com
Samsung semiconductor values product security. Check out the latest product security update at Samsung Semiconductor Global.
2
22
160
Qualcomm June 2025 Security Bulletin https://t.co/pD7SaUzvR9 "There are indications from Google TAG that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation"
12
12
58
๐iOS 18.4.1 dropped fixing a CoreAudio memory corruption and PAC bypass stating โthat this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.โ https://t.co/2cQFQM6rGF
support.apple.com
This document describes the security content of iOS 18.4.1 and iPadOS 18.4.1.
0
11
55
I found 2 UAF bugs in libxslt with Jackalope, let's find more together! The harness is now included in examples (link below). This also serves as a demo for two not very commonly used modes in Jackalope: grammar mutational fuzzing and sanitizer coverage.
0
34
153
๐จ UPDATE YOUR DEVICES ๐จ: Amnesty International uncovers sophisticated zero-day exploit affecting billions of Android devices. Cellebrite's Linux USB exploit was used to unlock the phone of a Serbian youth activist, targeted in December 2024 **after** previous reports abuses
4
198
499
I tweeted before about the Apple CoreAudio issues found by Google TAG. Well, the fuzz harness used to find these issues is now included in Jackalope examples, see https://t.co/nlVqpetOUN . Happy fuzzing! :)
The latest Apple security update contains fixes for three CoreAudio issues (CVE-2025-24160, CVE-2025-24161, CVE-2025-24163). These were found by Google Threat Analysis Group using Jackalope fuzzer.
2
40
185
BREAKING | WhatsApp has revealed that nearly 100 journalists and civil society members were targeted by Israeli spyware company Paragon Solutions, which used a โzero-clickโ method to secretly infect devices. The spyware, Graphite, provides full access to compromised devices,
155
2K
3K
The latest Apple security update contains fixes for three CoreAudio issues (CVE-2025-24160, CVE-2025-24161, CVE-2025-24163). These were found by Google Threat Analysis Group using Jackalope fuzzer.
1
20
96
As a New Year resolution, consider applying to Project Zero :)
It doesn't happen very often, but Project Zero is hiring! https://t.co/bA3FT6ZbzH Please share with anyone you think would be awesome for the role ๐ Looking for at least one person. DMs open if you want to reach out about the role. The team:
3
6
49
๐จ BREAKING: Amnestyโs latest report on digital surveillance in Serbia: new *NoviSpy* spyware discovered; zero days identified and patched; and first evidence showing use of Cellebrite UFED forensic products to unlock phones to then infect with spyware. ๐งต
9
335
889
If you've ever wondered if one can determine a vuln from just the kernel panic logs, @__sethJenkins (feat. @tehjh & @benoitsevens) have something to share: https://t.co/6ovPlKKI46 Great to collaborate with @amnesty, find vulns and get them fixed:
securitylab.amnesty.org
This is the Executive Summary of Amnesty Internationalโs report on surveillance and the suppression of civil society in Serbia. Please click here for the full report in PDF format. You can read the...
0
10
37
Apple patches two 0days marked as exploited on Intel-based Macs. Also fixed in new iOS 18.1.1 https://t.co/OV63n0fRpD
securityweek.com
Apple rushes out out major macOS and iOS security updates to cover a pair of vulnerabilities already being exploited in the wild.
2
8
23
Another big step towards becoming a security boundary: today weโre expanding the VRP for the V8 Sandbox * No longer limited to d8 * Rewards for controlled writes increased to $20k * Any memory corruption outside the sandbox now in scope https://t.co/LMTEEFZmT4 Happy hacking!
bughunters.google.com
ATTENTION As of 4 February 2024, Chromium has migrated to a new issue tracker, please report security bugs to the new issue tracker using this form . Please see the Chrome VRP News and FAQ page for...
1
42
153
The #HEXACON2024 talks have started to trickle in on YouTube, go check them out ๐ฅ: https://t.co/vizf0Jv8rf
youtube.com
2
44
104