BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: LaunchBreak: a Sip of Tea\, a Click\, and a Full Mul
 ti-stage\n   Desktop Takeover\n   Tags: DEF CON Official Talk | Demo ðŸ’» 
 | Tool ðŸ›  | Exploit ðŸª²\n   When: Sunday\, Aug 9\, 11:00 - 11:59 PDT\n 
   Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - [1]Map\n\n 
   Description:\n\n   As AI and agentic desktop apps rapidly adopt custom U
 RI schemes for\n   one-click onboardingâ€”MCP install\, plugin install\, c
 onfiguration\n   import\, prompt-driven actionsâ€”a browser click becomes 
 a gateway into\n   privileged local logic. Prior Electron research assumes
  the attacker\n   is already inside the app\; the browser-triggered\, end-
 to-end\n   exploitation model has remained unexplored.\n\n   We present La
 unchBreak: a class of vulnerabilities where a crafted\n   browser link lau
 nches a desktop app and injects attacker-controlled\n   input into a multi
 -stage\, multi-process exploit chain. We systematize\n   the attack surfac
 e across three dimensions: payload sources (URI\,\n   attacker server\, lo
 cal file)\, cross-process flows\n   (main/utility/renderer)\, and sinks (c
 ommand exec\, dynamic eval\, module\n   loading).\n\n   Our findings inclu
 de 18 zero-days\, 17 of them full RCEs\, with 11 CVEs\n   and a bug bounty
 . The affected apps include AFFiNE (60k stars\,\n   CVE-2026-21853)\, Hype
 r (Vercel's terminal\, bounty awarded)\, Cherry\n   Studio (CVE-2025-54063
 )\, Pinokio (CVE-2025-44109)\, deepchat\n   (CVE-2025-55733)\, Paperlib (C
 VE-2025-64743)\, and more\, spanning AI\n   assistants\, music players\, a
 nd dev tools. We'll demo live exploits\n   against apps\, walk through the
  chains\, and release Proton\, the\n   agent-guided segmented fuzzing fram
 ework we built to find them\, plus\n   PoCs for every vulnerability.\n\n  
  The related CCS paper if that submission is accepted (the result comes\n 
   out in June.)\, if not\, then none.\n\n   Speakers:Gavin Zhong\,Zhengyu 
 Liu\,Jianjia Yu\n\n   SpeakerBio:  Gavin Zhong\, Johns Hopkins University\
 n\n   Jiacheng (Gavin) Zhong is a security researcher\, focusing on AI sys
 tem\n   security\, program analysis\, and identity security. He recently\n
    completed his M.S. in Security Informatics at Johns Hopkins\n   Univers
 ity\, where his work was accepted to IEEE S&P 2026. Gavin has\n   reported
  over 30 CVEs in widely used open-source projects. He is also\n   an activ
 e CTF player with r3kapig\, an international team ranked top 3\n   worldwi
 de.\n\n   SpeakerBio:  Zhengyu Liu\, Johns Hopkins University\n\n   Zhengy
 u Liu is a third-year PhD student in Computer Science at Johns\n   Hopkins
  University. His research focuses on web and software security\n   via pro
 gram analysis. His work received Distinguished Paper (S&P\n   â€™25)\, Hon
 orable Mention (USENIX â€™25)\, and Best Student Paper\n   (ICICS â€™22). 
 He is a DEF CON speaker and is a member of CTF team\n   TheHackersCrew.\n\
 n   SpeakerBio:  Jianjia Yu\, Johns Hopkins University\n\n   Jianjia Yu is
  a PhD student at Johns Hopkins University\, advised by\n   Prof. Yinzhi C
 ao. Her research focuses on security and privacy in web\n   and mobile eco
 systems using program analysis techniques. Her work has\n   received Disti
 nguished Paper Awards at CCS '23 and S&P '25\, and an\n   Honorable Mentio
 n at USENIX Security '25. She has discovered over 40\n   zero-day vulnerab
 ilities and uncovered privacy leaks affecting\n   millions of users across
  browser extensions and mobile applications.\n\n   '\n\n   1. #LVCCW_Level
 1_Hall3\n\n\n
DTEND:20260809T185900Z
DTSTART:20260809T180000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-
 1
SUMMARY:LaunchBreak: a Sip of Tea\, a Click\, and a Full Multi-stage Deskto
 p Takeover
END:VEVENT
END:VCALENDAR
