BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Compiler That Can't Read: Crashing Every 5G Phon
 e With One\n   Byte\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 
 🪲\n   When: Saturday\, Aug 8\, 16:00 - 16:59 PDT\n   Where: LVCCW Level
  1 Hall 3 903 (Main Track 5) and DCTV-5 - [1]Map\n\n   Description:\n\n   
 Every 5G phone parses radio messages using code generated by a\n   compile
 r. That compiler has two blind spots — and we used them to\n   crash iPh
 ones\, Pixels\, and phones from every major chipset vendor. No\n   credent
 ials\, no user interaction\, no warning.\n\n   The compiler can't read Eng
 lish. Hundreds of rules that govern when\n   fields should appear exist on
 ly in natural-language prose. The\n   compiler discards them all. We extra
 cted these invisible rules\, turned\n   them into targeted payloads\, and 
 crashed basebands from Apple\, Google\,\n   Qualcomm\, and MediaTek — al
 l before authentication. Apple confirmed\n   reproduction. Google Android 
 Security confirmed multiple findings.\n   MediaTek patched three CVEs affe
 cting 64 chipset models and over 542\n   smartphone models. Qualcomm rewar
 ded one finding.\n\n   The compiler can't count. Some fields have value ra
 nges that don't\n   fill the wire encoding. We changed one byte in a legit
 imate message\n   and crashed phones across two chipset generations. GSMA 
 assigned\n   CVD-2025-0110.\n\n   Same root cause\, same blind compiler\, 
 same result: the modem trusts a\n   decoder that was never built to enforc
 e the rules that matter. We demo\n   live over-the-air crashes on stage.\n
 \n     1. 3GPP TS 38.331: NR Radio Resource Control (RRC) protocol\n      
  specification\n\n     2. 3GPP TS 33.501: Security architecture and proced
 ures for 5G\n       System\n\n     3. ITU-T X.680-X.693: ASN.1 and encodin
 g rules (UPER)\n\n     4. Hernandez et al.\, "FirmWire: Transparent Dynami
 c Analysis for\n       Cellular Baseband Firmware\," NDSS 2022\n\n     5. 
 Klischies et al.\, "BaseBridge: Bridging the Gap Between\n       Over-the-
 Air and Emulation Testing for Cellular Baseband\n       Firmware\," IEEE S
 &P 2025\n\n     6. Garbelini et al.\, "5Ghoul: Unleashing Chaos on 5G Edge
  Devices\,"\n       IEEE TDSC 2025\n\n     7. Park et al.\, "DoLTEst: In-d
 epth Downlink Negative Testing\n       Framework for LTE Devices\," USENIX
  Security 2022\n\n     8. Rupprecht et al.\, "Putting LTE Security Functio
 ns to the Test: A\n       Framework to Evaluate Implementation Correctness
 \," USENIX WOOT\n       2016\n\n   Speakers:Qiqing Huang\,Xingyu Wang\n\n 
   SpeakerBio:  Qiqing Huang\n\n   Qiqing Huang is a PhD candidate in Compu
 ter Science at the University\n   at Buffalo\, specializing in 5G baseband
  security. His research focuses\n   on exploiting structural gaps between 
 formal protocol schemas and\n   natural-language specification constraints
  to discover\n   pre-authentication vulnerabilities in commercial cellular
  modems. His\n   work has resulted in multiple high-severity CVEs affectin
 g major\n   baseband vendors including Apple\, Qualcomm\, Samsung\, and Me
 diaTek\,\n   impacting 64 chipset models and over 542 commercially availab
 le\n   smartphone models. He received GSMA CVD-2025-0110 for discovering a
 \n   class of ASN.1 decode divergence vulnerabilities. His research has\n 
   been published at USENIX Security 2026. He maintains active\n   responsi
 ble disclosure relationships with Apple\, Google\, Qualcomm\,\n   Samsung\
 , MediaTek\, and GSMA. He is completing his PhD in Summer 2026\n   and is 
 on the job market for security research roles.\n\n   SpeakerBio:  Xingyu W
 ang\, University at Buffalo\n\n   Xingyu Wang is a PhD student at the Univ
 ersity at Buffalo studying the\n   weird edge cases of networks\, phones\,
  and systems that are supposed to\n   “just work.” He explores how AI 
 can help security researchers\n   survive dense specs and turn “wait\, w
 hy did it do that?” moments\n   into better tests. He does not fully tru
 st AI or complex systems\, but\n   he enjoys putting them in the same room
  and watching what breaks\n   first.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\
 n\n\n
DTEND:20260808T235900Z
DTSTART:20260808T230000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:The Compiler That Can't Read: Crashing Every 5G Phone With One Byte
END:VEVENT
END:VCALENDAR
