Tech lead and security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own. Backup @ifsecure@infosec.exchange

The slides for my Black Hat talk "XMPP Stanza Smuggling or How I Hacked Zoom" are now available at blackhat.com/us-22/briefings…
4
67
280
When an elevator closes, but a stairwell remains open
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed β€œDark Elevator”. But was it really fixed? Ask @tiraniddo projectzero.google/2026/09/w…
22
3,711
Ivan Fratric πŸ’™πŸ’› retweeted
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed β€œDark Elevator”. But was it really fixed? Ask @tiraniddo projectzero.google/2026/09/w…
3
46
210
16,881
New race condition tooling by @tehjh!
Today, Project Zero is releasing MAccConc, a tool by @tehjh that enables deterministic testing of race conditions on Linux. It can be used for fuzzing, ad-hoc exploration, regression tests and more! projectzero.google/2026/09/m…
2
18
2,784
At this year's OffensiveCon, @R00tkitSMM quite correctly pointed out to me that, on Apple devices, MTE can be used to get more reliable crashes while fuzzing. He also pointed out that Jackalope/TinyInst does not support binaries with MTE enabled and crashes. (1/2)
2
9
80
8,818
The latest TinyInst includes a quick fix for that. It worked in my experiments, but if you encounter any other issues, please report them. Good for me that there is only one place in the TinyInst codebase from which all target process memory is read and written :) (2/2)
10
1,257
In case you missed it!
Project Zero is hiring! google.com/about/careers/app… Please share with anyone you think would be great for the role. DMs are open for questions.
1
35
9,063
Ivan Fratric πŸ’™πŸ’› retweeted
Finally it got published.
We found a working remote Spectre attack against Cloudflare Workers. We already fixed it. No exploitation in the wild. Blog post and paper out now: cfl.re/4qKdP6V
6
69
9,051
Ivan Fratric πŸ’™πŸ’› retweeted
My and @natashenka 's talk from OffensiveCon is now available on YouTube! Watch for a tour of a zero-click to root exploit chain across multiple generations of Google Pixel! piped.video/watch?v=jpB_b6KG…
1
25
82
11,019
Ivan Fratric πŸ’™πŸ’› retweeted
Offensivecon's talks are now available on our YouTube channel! πŸ”— buff.ly/g63xgm5
1
100
343
25,938
It is true that you can query (e.g. via curl) a server and get a redirect url *if* that redirect url is not user-specific. However the idea of the talk was to leak redirect urls that contain sensitive information (such as the OAath access token in my 1st demo).
6
2,633
Turns out adapting our 0click chain to work on Pixel 10 wasn't that hard... at least if you're into Android drivers as much as @__sethJenkins.
.@__sethJenkins updated our 0-click exploit chain to work on a Pixel 10 with an eye-popping driver bug! We’ll be presenting this work Saturday @offensive_con projectzero.google/2026/05/p…
2
22
3,589
CVE-2026-28920 (Apple, zlib, found by Brendon Tiszka of Google Project Zero) sure looks fun :)
1
12
97
12,483
Ivan Fratric πŸ’™πŸ’› retweeted
The fuzzer that found project-zero.issues.chromium… (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844 It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
4
95
481
40,208
Ivan Fratric πŸ’™πŸ’› retweeted
Just derestricted a now-fixed kernel bug in Pixel 10. I think this ranks as the most easily exploited kernel bug of all time😬 Thanks to @tehjh for collab'ing on this driver and full credits for noticing this bug in the first 5 minutes of auditingπŸ˜‚ project-zero.issues.chromium…
5
45
187
17,563
I wrote a short blogpost on the quirks of grammar fuzzing (and, more generally, structure-aware fuzzing) and a simple trick I used to get more bugs out of it more quickly. projectzero.google/2026/03/m…
4
48
186
12,824
Jackalope and Tinyinst have been working on arm64 macs for a while, but now you should also be able to run against arm64e binaries (i.e. binaries that ship with the os) with some modification to the system. For details, see github.com/googleprojectzero…
2
23
124
7,795
Ivan Fratric πŸ’™πŸ’› retweeted
In the final part of his blog series, @tiraniddo tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/g…
54
190
21,541
How a single feature was responsible for 5 Windows Administrator Protection bypasses, in a new Project Zero blog post by @tiraniddo
Part 2 of @tiraniddo’s Windows Administrator Protection journey is here! projectzero.google/2026/02/w…
9
39
7,294