Go offline with the Player FM app!
Recycling Exploits in MacOS and Pirating Audiobooks
Manage episode 467244182 series 2606557
We cover a comical saga of vulnerabilities and variants from incomplete fixes in macOS, as well as a bypass of Chrome's miraclePtr mitigation against Use-After-Frees (UAFs). We also discuss an attack that abuses COM hijacking to elevate to SYSTEM through AVG Antivirus, and a permissions issue that allows unauthorized access to DRM'd audiobooks.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/273.html
[00:00:00] Introduction
[00:00:23] Attacking Hypervisors From KVM to Mobile Security Platforms
[00:01:35] Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times
[00:11:02] The Most "Golden" Bypass of 2024
[00:44:55] Leaking the email of any YouTube user for $10,000
[01:11:52] Unmasking Cryptographic Risks: A Deep Dive into the Nym Audit w/ Nadim Kobeissi
Podcast episodes are available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
281 episodes
Manage episode 467244182 series 2606557
We cover a comical saga of vulnerabilities and variants from incomplete fixes in macOS, as well as a bypass of Chrome's miraclePtr mitigation against Use-After-Frees (UAFs). We also discuss an attack that abuses COM hijacking to elevate to SYSTEM through AVG Antivirus, and a permissions issue that allows unauthorized access to DRM'd audiobooks.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/273.html
[00:00:00] Introduction
[00:00:23] Attacking Hypervisors From KVM to Mobile Security Platforms
[00:01:35] Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times
[00:11:02] The Most "Golden" Bypass of 2024
[00:44:55] Leaking the email of any YouTube user for $10,000
[01:11:52] Unmasking Cryptographic Risks: A Deep Dive into the Nym Audit w/ Nadim Kobeissi
Podcast episodes are available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
281 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.