BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Gone in 60 Frames – USB Video Exploitation\n   Tag
 s: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   When: Sunday\, Aug
  9\, 11:00 - 11:59 PDT\n   Where: LVCCW Level 1 Hall 3 903 (Main Track 5) 
 and DCTV-5 - [1]Map\n\n   Description:\n\n   In 2025\, Amnesty Internation
 al\, in collaboration with Google TAG\,\n   released a write-up of an in-t
 he-wild chain of USB Linux kernel\n   vulnerabilities which was used to co
 mpromise mobile devices.\n\n   Whilst the vulnerabilities themselves were 
 disclosed\, no details on\n   how these vulnerabilities could be exploited
  were provided. This led\n   us to deep dive into these issues to determin
 e how they could be\n   leveraged for arbitrary code execution.\n\n   This
  is the story of exploiting one of these vulnerabilities\n   (CVE-2024-531
 04)\, an out of bounds write in USB Video which offered a\n   brilliant ex
 ploit primitive leading to highly reliable code execution\n   when chained
  together with an information leakage vulnerability.\n\n   In this talk we
  will first discuss the in-the-wild vulnerabilities\,\n   moving on to pro
 viding background of USB specifics for several device\n   classes and cove
 rage guided fuzzing for finding new issues.\n\n   We will then move onto a
  more recent information disclosure\n   vulnerability CVE-2025-38494 which
  could be leveraged to bypass KASLR.\n\n   An extensive deep dive into CVE
 -2024-53104 vulnerability will be\n   performed (the OOB write) and we wil
 l discuss our novel technique used\n   for exploitation of this issue and 
 expose the power of the\n   UVC_QUIRK_RESTRICT_FRAME_RATE quirk!\n\n   Fin
 ally\, we will wrap up our talk with several demonstrations.\n\n   Speaker
 s:Alex Plaskett\,Robert Herrera\n\n   SpeakerBio:  Alex Plaskett\, NCC Gro
 up\n\n   Alex Plaskett (@alexjplaskett) is an Associate Director within th
 e\n   Exploit Development Group (EDG) at NCC Group. Alex is a five-time\n 
   Pwn2Own winner (desktop\, mobile\, embedded\, and automotive) and has\n 
   over 16+ years of experience in vulnerability research and\n   exploitat
 ion. Alex has exploited vulnerabilities in a large range of\n   high-profi
 le products across many different areas of security. Alex is\n   a frequen
 t speaker at security conferences (e.g. BlackHat\,\n   OffensiveCon\, Hexa
 con\, HITB\, BlueHat\, POC\, Troopers etc). Alex was\n   previously leadin
 g security teams in Fintech\, Mobile Security and\n   Security Research) a
 nd just generally causing vendors to patch things\n   on a regular basis!\
 n\n   SpeakerBio:  Robert Herrera\, NCC Group\n\n   Robert Herrera (@rober
 t.herrera_) is a Lead Security Researcher within\n   the Exploit Developme
 nt Group (EDG) at NCC Group. Robert has extensive\n   experience performin
 g high-impact security audits and\n   reverse-engineering for a diverse se
 t of technologies ranging from\n   automotive\, modems\, secure boot platf
 orms\, and wireless technologies.\n   Robert has 9+ years of experience an
 d has worn many hats over the\n   years ranging from iOS Developer\, Softw
 are Engineer\, to Reverse\n   Engineer.\n\n   '\n\n   1. #LVCCW_Level1_Hal
 l3\n\n\n
DTEND:20260809T185900Z
DTSTART:20260809T180000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:Gone in 60 Frames – USB Video Exploitation
END:VEVENT
END:VCALENDAR
