Natalie Silvanovich
@natashenka.bsky.social
š¤ 691
š„ 184
š 65
Google Project Zero
Thereās a little piece of my heart that beats just for Spanify
groups.google.com/a/chromium.o...
loading . . .
Introducing Spanification
https://groups.google.com/a/chromium.org/g/chromium-dev/c/iEy69ygz-rs
11 days ago
0
2
0
Amazing work by Meta implementing fast and robust WebRTC updates! āWe canāt push updates because ā¦ā can often be solved with investment and innovative engineering
engineering.fb.com/2026/04/09/d...
loading . . .
Escaping the Fork: How Meta Modernized WebRTC Across 50+ Use Cases
At Meta, WebRTC powers real-time audio and video across various platforms. But forking a large open-source project like WebRTC within our monorepo presents unique challenges ā over time, an internaā¦
https://engineering.fb.com/2026/04/09/developer-tools/escaping-the-fork-how-meta-modernized-webrtc-across-50-use-cases/
16 days ago
1
1
0
Just put a reminder in my calendar for November 1, 2026 to check whether we still have bugs
29 days ago
1
4
0
reposted by
Natalie Silvanovich
about 2 months ago
Mountain View Reverse Engineering (mtvre) meetup on Wed! 7:00 pm at Wagon Wheel BBQ. Talks: -
@tubetime.bsky.social
on "HP 16717 PCB Reverse Engineering" (40 min) -
@natashenka.bsky.social
on "0-click Android exploits" (25 min)
1
5
3
Ivan Fratric shares some tips and tricks for grammar fuzzing
projectzero.google/2026/03/muta...
loading . . .
On the Effectiveness of Mutational Grammar Fuzzing
Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar t...
https://projectzero.google/2026/03/mutational-grammar-fuzzing.html
about 2 months ago
0
7
4
about 2 months ago
0
1
0
In the final part of his blog series,
@tiraniddo.dev
tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but itās important not to forget the security properties the code needs to enforce in the process.
projectzero.google/2026/02/gphf...
loading . . .
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didnāt know existed until I found a publicly disclosed UAC bypass us...
https://projectzero.google/2026/02/gphfh-deep-dive.html
2 months ago
0
5
4
Part 2 of
@tiraniddo.dev
ās Windows Administrator Protection journey is here!
projectzero.google/2026/02/wind...
loading . . .
Bypassing Administrator Protection by Abusing UI Access - Project Zero
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didnāt exi...
https://projectzero.google/2026/02/windows-administrator-protection.html
3 months ago
1
5
5
The remarkable true story of how Flash was deprecated
medium.com/@aglaforge/w...
loading . . .
What Really Killed Flash Player: A Six-Year Campaign of Deliberate Platform Work
This is what it actually took. From the person who architected and drove Chromeās Flash deprecation from proposal to the final removal inā¦
https://medium.com/@aglaforge/what-really-killed-flash-player-a-six-year-campaign-of-deliberate-platform-work-279d491633f9
3 months ago
1
5
3
Our intrepid 20%-er Dillon Franke exploited a vulnerability in CoreAudio. See his process for gaining privilege escalation on a Mac:
projectzero.google/2026/01/soun...
loading . . .
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 - Project Zero
In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-...
https://projectzero.google/2026/01/sound-barrier-2.html
3 months ago
0
7
1
No security feature is perfect.
@tiraniddo.dev
reviewed Windowsā new Administrator Protection and found several bypasses.
projectzero.google/2026/26/wind...
loading . . .
Bypassing Windows Administrator Protection - Project Zero
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Cont...
https://projectzero.google/2026/26/windows-administrator-protection.html
3 months ago
0
5
5
Some extra 0-click fun! Seth Jenkins and I trying to figure out why our exploit isnāt working, when it has, in fact, already started taking and exfiltrating photos
3 months ago
0
8
0
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices.
projectzero.google/2026/01/pixe...
loading . . .
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
https://projectzero.google/2026/01/pixel-0-click-part-1.html
3 months ago
1
58
37
But wait, I havenāt read all the āBest Books of 2024ā yet
4 months ago
0
5
1
Thank you, we love the design š
add a skeleton here at some point
4 months ago
0
4
0
We launched a redesigned Project Zero website today at
projectzero.google
! To mark the occasion, we released some older posts that never quite made it out of drafts. Enjoy!
loading . . .
Google Project Zero
Make zeroday hard
https://projectzero.google
4 months ago
0
18
5
An analysis of a recent 0-click exploit targeting Samsung devices:
googleprojectzero.blogspot.com/2025/12/a-lo...
loading . . .
A look at an Android ITW DNG exploit
Posted by BenoƮt Sevens, Google Threat Intelligence Group Introduction Between July 2024 and February 2025, 6 suspicious image files were ...
https://googleprojectzero.blogspot.com/2025/12/a-look-at-android-itw-dng-exploit.html
5 months ago
1
7
5
Crime show: āWe know the victim died at night because we found beef in his stomach.ā Me, shoving a left-over burger in my face at 7am: š«¢
5 months ago
2
4
0
Your phoneās more likely to hit the ASLR state you need if you put a lucky dragon on it
5 months ago
0
3
0
I love how my city sends me text message alerts when thereās the chance to see a sinkhole
5 months ago
0
0
0
New Blog Post: Seth Jenkins broke kASLR by doing ⦠nothing š©
googleprojectzero.blogspot.com/2025/11/defe...
loading . . .
Defeating KASLR by Doing Nothing at All
Posted by Seth Jenkins, Project Zero Introduction I've recently been researching Pixel kernel exploitation and as part of this research I ...
https://googleprojectzero.blogspot.com/2025/11/defeating-kaslr-by-doing-nothing-at-all.html
6 months ago
0
10
5
Serious bugs often occur in third-party components integrated by other software. Ivan Fratric and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click.
project-zero.issues.chromium.org/issues/42807...
loading . . .
Project Zero
https://project-zero.issues.chromium.org/issues/428075495
6 months ago
1
10
1
Super cool potential ASLR leak involving dictionary hashes!
googleprojectzero.blogspot.com/2025/09/poin...
loading . . .
Pointer leaks through pointer-keyed data structures
Posted by Jann Horn, Google Project Zero Introduction Some time in 2024, during a Project Zero team discussion, we were talking about how...
https://googleprojectzero.blogspot.com/2025/09/pointer-leaks-through-pointer-keyed.html
7 months ago
0
10
6
fseek and you shall lfind
8 months ago
0
1
0
reposted by
Natalie Silvanovich
Lorenzo Franceschi-Bicchierai
9 months ago
Zero-day developer and seller Exodus casually brags in a blog post about having found a WebKit zero-day and sold it for a year and a half.
blog.exodusintel.com/2025/08/04/o...
ClƩment Lecigne and BenoƮt Sevens of Google's Threat Analysis Group were the ones that reported it to Apple.
1
21
10
Left blue, right red
#defcon
9 months ago
0
3
0
How to use your Defcon badge
9 months ago
1
4
1
āYou wouldnāt happen to have anything that could help me understand todayās ever-changing threat landscape? Perhaps involving a bit of AI?ā
9 months ago
0
3
1
Peak BH slide
9 months ago
0
1
0
Do you ever feel like maybe you should sign something, but arenāt quite sure you can follow through?
9 months ago
0
4
0
We also posted our first Transparency Report
googleprojectzero.blogspot.com/p/reporting-...
loading . . .
Reporting Transparency
As part of our 2025 Policy Trial , Project Zero will use this page to publicly track our Reporting Transparency effort. The trial commenced ...
https://googleprojectzero.blogspot.com/p/reporting-transparency.html
9 months ago
0
3
1
While most vendors ship timely patches for vulnerabilities reported by Project Zero, they donāt always reach users. Today, weāre announcing Reporting Transparency, a new policy to encourage downstream fixes
googleprojectzero.blogspot.com/2025/07/repo...
loading . . .
Policy and Disclosure: 2025 Edition
Posted by Tim Willis, Google Project Zero In 2021, we updated our vulnerability disclosure policy to the current "90+30" model. Our goals we...
https://googleprojectzero.blogspot.com/2025/07/reporting-transparency.html
9 months ago
1
6
9
reposted by
Natalie Silvanovich
Microplastics Sommelier
9 months ago
maybe there's still some good left in this world after all
loading . . .
311
17280
4912
The new Tamagotchi Switch game has rap battles where the Tamas rap about how they respect and enjoy each othersā unique differences
10 months ago
0
3
0
reposted by
Natalie Silvanovich
lukelukeluke
10 months ago
Inventor of the GIF, hearing about Notre Dame burning: oh no the jarjoyles
70
5293
1245
reposted by
Natalie Silvanovich
Dr. Jen Gunter
10 months ago
I accidentally closed a browser yesterday with 72 VERY IMPORTANT TABS that have been following me around like Jacob Marley and somehow my history is not recoverable. Reader, I let them go, and have lived to tell the tale.
30
429
14
At least 3 miles of protesters along El Camino in Sunnyvale
11 months ago
1
6
0
I Googled āhow to shorten a chain,ā and got no good answers, so hereās the answer, hereās how you temporarily shorten it
11 months ago
0
1
0
reposted by
Natalie Silvanovich
Pookleblinky
11 months ago
www.ibiblio.org/harris/500mi...
You might be one of the lucky people to learn today about an emailing bug that turned out to be caused by the speed of light.
loading . . .
The case of the 500-mile email
https://www.ibiblio.org/harris/500milemail.html
2
43
16
If thereās one thing Iāve learned, itās that tab completion is never ājust broken todayā
11 months ago
0
0
0
11 months ago
0
2
0
If $106,050.10 was the size of a quarter, it would fit in 424,200.4 fewer shipping containers than ā¦
11 months ago
0
0
0
The world never says hello back
11 months ago
2
8
2
The final part of Mateuszās Windows Registry series is live! Contains all the hive memory corruption exploitation youāve been waiting for
googleprojectzero.blogspot.com/2025/05/the-...
loading . . .
The Windows Registry Adventure #8: Practical exploitation of hive memory corruption
Posted by Mateusz Jurczyk, Google Project Zero In the previous blog post , we focused on the general security analysis of the registry a...
https://googleprojectzero.blogspot.com/2025/05/the-windows-registry-adventure-8-exploitation.html
11 months ago
0
6
4
reposted by
Natalie Silvanovich
DistrictCon
11 months ago
šØ CALLING ALL VULNERABILITY RESEARCHERS šØ The Junkyard is officially open! This is our live, on-stage pwnathon dedicated to end-of-life systems. Submit your bugs! Prizes range from $100 to $5,000 for categories like: āļø Most Impactful System š¾ Best Meme Target š Most Engaging Presentation
1
20
18
Movie you've watched more than 1000 times using gifs. ("Hard mode" no Star Wars, Star Trek, or LoTR)
add a skeleton here at some point
about 1 year ago
0
1
0
Should be a Canada goose
about 1 year ago
0
2
0
reposted by
Natalie Silvanovich
RE//verse
about 1 year ago
Another must-watch talk from RE//verse 2025 is live! Zion Basque challenges decompilers to step up their game and introduces a roadmap for a practical solution to solve some of the trickiest compiler behavior's to analyze. Check it out here:
loading . . .
RE//verse 2025: Buccaneers of the Binary (Zion Basque)
Full Title: Buccaneers of the Binary: Plundering Compiler Optimizations for Decompilation Treasure. Zion's talk is both a challenge for decompilers to step up ...
https://youtu.be/VP29biKLoSw
0
7
2
about 1 year ago
1
5
0
Load more
feeds!
log in