Tech lead and security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own.
Backup @ifsecure@infosec.exchange
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed βDark Elevatorβ.
But was it really fixed?
Ask @tiraniddoprojectzero.google/2026/09/wβ¦
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed βDark Elevatorβ.
But was it really fixed?
Ask @tiraniddoprojectzero.google/2026/09/wβ¦
Today, Project Zero is releasing MAccConc, a tool by @tehjh that enables deterministic testing of race conditions on Linux. It can be used for fuzzing, ad-hoc exploration, regression tests and more!
projectzero.google/2026/09/mβ¦
At this year's OffensiveCon, @R00tkitSMM quite correctly pointed out to me that, on Apple devices, MTE can be used to get more reliable crashes while fuzzing. He also pointed out that Jackalope/TinyInst does not support binaries with MTE enabled and crashes. (1/2)
The latest TinyInst includes a quick fix for that. It worked in my experiments, but if you encounter any other issues, please report them. Good for me that there is only one place in the TinyInst codebase from which all target process memory is read and written :) (2/2)
We found a working remote Spectre attack against Cloudflare Workers. We already fixed it. No exploitation in the wild. Blog post and paper out now:
cfl.re/4qKdP6V
My and @natashenka 's talk from OffensiveCon is now available on YouTube! Watch for a tour of a zero-click to root exploit chain across multiple generations of Google Pixel!
piped.video/watch?v=jpB_b6KGβ¦
It is true that you can query (e.g. via curl) a server and get a redirect url *if* that redirect url is not user-specific. However the idea of the talk was to leak redirect urls that contain sensitive information (such as the OAath access token in my 1st demo).
The fuzzer that found project-zero.issues.chromium⦠(and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844
It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
Just derestricted a now-fixed kernel bug in Pixel 10. I think this ranks as the most easily exploited kernel bug of all timeπ¬
Thanks to @tehjh for collab'ing on this driver and full credits for noticing this bug in the first 5 minutes of auditingπ
project-zero.issues.chromiumβ¦
I wrote a short blogpost on the quirks of grammar fuzzing (and, more generally, structure-aware fuzzing) and a simple trick I used to get more bugs out of it more quickly. projectzero.google/2026/03/mβ¦
Jackalope and Tinyinst have been working on arm64 macs for a while, but now you should also be able to run against arm64e binaries (i.e. binaries that ship with the os) with some modification to the system. For details, see github.com/googleprojectzeroβ¦
In the final part of his blog series, @tiraniddo tells the story of how a bug was introduced into a Windows API.
Code re-writes can improve security, but itβs important not to forget the security properties the code needs to enforce in the process.
projectzero.google/2026/02/gβ¦