tags:firefoxOOB_readOOB_write original link: Exploiting a SpiderMonkey: From Integer Range Inconsistency to Bound Check Elimination then RCE newsletter link: exploits.club Weekly Newsletter 28


Exploits Club Summary:

@bjrjk published a set of slides this week walking through the background, RCA, exploit for CVE-2024-29943. The bug was originally used by @_manfp in Pwn2Own and later analyzed by @maxspl0it. We also want to give a shout-out to the quality of the slides - this deck is “make-your-asshole-McKinsey-cousin-drool” type stuff.