Hacker News new | past | comments | ask | show | jobs | submit login




That's a different bug (CVE-2024-0517 vs CVE-2024-0519)


I’m pretty sure the chain is all three bugs. 517, 518, 519.


I'm pretty sure it isn't, the write up only uses 517 to get an arbitrary write primitive and then did a pretty standard chain into a sandbox escape via wasm (disclaimer - I work on V8).


Hmm. I also thought the type confusion in 518 was the same one from the blog post, but looking at the patch, it's not either. I think I stand corrected overall.


I wonder if they got a bounty from it?


Exodus sells vulnerabilities to the government.


To quote their "ethics" statement:

"We pride ourselves in our skillsets to parallel those of nation state hacking groups, and we tout that our expertise is unrivaled in our ability to discover and exploit vulnerabilities in a variety of product.

Our intention as a Company is to provide this intelligence to US and Allied countries for their enterprise and governments to have a leg up over the malicious actors from around the world."

Ouch.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: