5 ms·
Seems low considering the wide impact, but maybe the only thing corporations throw big money at is remote exploits?
by mrbluecoat 2mo ago
Seems low considering the wide impact, but maybe the only thing corporations throw big money at is remote exploits?
- tptacek 2mo agoThat's a huge amount of money for a vulnerability.
- esseph 2mo agohttps://www.forbes.com/sites/daveywinder/2026/05/05/google-to-pay-15-million-for-pixel-phone-security-exploit/ https://www.forbes.com/sites/daveywinder/2026/05/05/google-t...
- inigyou 2mo agoAlso one order of magnitude less than you could get on the black market for a universal Linux LPE and two orders less if you can make it work reliably.
- tptacek 2mo agoI believe you are two orders of magnitude wrong, in the upward direction, on that number (the first of them). You're talking about reliable remote numbers there, full chain, full enablement, tranched with maintenance.
- inigyou 2mo agoSurely working on Android adjusts the number upwards by a lot?
- deleted 2mo ago[deleted]
- ActorNightly 2mo agoHow is it a wide impact? It requires being able to execute arbitrary code on the machine in userspace. If you have that, most of the time you don't even care about kernel level exploits.
- etenal 2mo agoIt's a browser to kernel full chain exploit, from url click to root your device.
- ActorNightly 2mo agoNo, GhostLock is not browser to Kernel. https://nebusec.ai/research/v8-maglev-incorrect-phis-untagging/ https://nebusec.ai/research/v8-maglev-incorrect-phis-untaggi... This is the browser part.
- athrowaway3z 2mo agohttps://rootme.nebusec.io/ https://rootme.nebusec.io/
- ActorNightly 2mo ago> Step1. Download Vulnerable Firefox. Please tell me you are trolling me and not this stupid.
- fragmede 2mo agoI think you are misunderstanding the objective.
- netheril96 2mo agoSupposedly it can root Android.