BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Patch Gap to Mobile Renderer RCE: Pwning Samsung Int
 ernet's V8\n   on the Galaxy S25\n   Tags: DEF CON Official Talk | Demo ðŸ
 ’» | Exploit ðŸª²\n   When: Friday\, Aug 7\, 12:30 - 13:30 PDT\n   Where: 
 LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]Map\n\n   Descript
 ion:\n\n   What happens when a flagship phone like the Samsung Galaxy S25 
 ships\n   with an outdated Javascript engine in its default browser?\n\n  
  For the past 6 months\, Samsung Internet shipped with an out-of-date V8\n
    build that had already-fixed\, publicly known vulnerabilities. One such
 \n   bug is CVE-2025-10891\, a flaw in Ignition bytecode generation for\n 
   Javascript exception handling. In this talk\, we show how we transform\n
    this vulnerability into reliable renderer code execution through\n   in
 struction smuggling and internal native V8 runtime calls. We then\n   show
 case how we exploit weaker isolation mechanisms on mobile Chromium\n   eng
 ines to upgrade the renderer RCEâ€™s capability into a universal\n   XSS p
 rimitive.\n\n   https://osec.io/blog/2026-04-01-patch-gap-to-mobile-render
 er-rce/\n   https://issuetracker.google.com/issues/443875388\n\n   Speaker
 s:Hrvoje MiÅ¡etiÄ‡\,Jamie Hill-Daniel\,William Liu\n\n   SpeakerBio:  Hrvo
 je MiÅ¡etiÄ‡\, OtterSec\n\n   Hrvoje MiÅ¡etiÄ‡ is a Web3 auditor and secur
 ity researcher at OtterSec\n   with prior research projects including Linu
 x kernel LPE\, QEMU\n   hypervisor escape\, and browser exploitation. He i
 s a member of the\n   Crusaders of Rust CTF team\, and DiceGang\, with who
 m he has qualified\n   for Defcon CTF Finals multiple times. He presented 
 Minecraft RCE\n   research at OffensiveCon â€˜26.\n\n   SpeakerBio:  Jamie
  Hill-Daniel\, OtterSec\n\n   Jamie Hill-Daniel is a security auditor curr
 ently working at OtterSec\,\n   with an interest in browser and kernel res
 earch. He is a member of the\n   Crusaders of Rust and DiceGang CTF teams\
 , having qualified for\n   multiple Defcon CTF Finals with the latter.\n\n
    SpeakerBio:  William Liu\n\n   William Liu is a security engineer at Tr
 ail of Bits with experience in\n   low-level systems and computer architec
 ture. He is a member of the\n   Crusaders of Rust and DiceGang CTF teams\,
  having qualified for\n   multiple Defcon CTF Finals with the latter. He h
 as previously worked\n   as a systems software engineer at NVIDIA. He docu
 ments some of his\n   research on his personal site\, willsroot.io.\n\n   
 William is a Class of 2025 graduate of the Massachusetts Institute of\n   
 Technology\, where he worked on the EntryBleed KASLR bypass and kernel\n  
  fuzzing under Professor Mengjia Yan. He has presented\n   micro-architect
 ural security research at HASP â€˜23 and NEHWS â€˜24\,\n   as well as Linu
 x 0-day research at Hexacon â€˜25.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\
 n\n
DTEND:20260807T203000Z
DTSTART:20260807T193000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet's V8 on t
 he Galaxy S25
END:VEVENT
END:VCALENDAR
