Natalie Silvanovich
@natashenka.bsky.social
đ¤ 644
đĽ 184
đ 55
Google Project Zero
Some extra 0-click fun! Seth Jenkins and I trying to figure out why our exploit isnât working, when it has, in fact, already started taking and exfiltrating photos
4 days ago
0
8
0
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices.
projectzero.google/2026/01/pixe...
loading . . .
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
https://projectzero.google/2026/01/pixel-0-click-part-1.html
4 days ago
1
57
36
But wait, I havenât read all the âBest Books of 2024â yet
19 days ago
0
5
1
Thank you, we love the design đ
add a skeleton here at some point
about 1 month ago
0
4
0
We launched a redesigned Project Zero website today at
projectzero.google
! To mark the occasion, we released some older posts that never quite made it out of drafts. Enjoy!
loading . . .
Google Project Zero
Make zeroday hard
https://projectzero.google
about 1 month ago
0
17
5
An analysis of a recent 0-click exploit targeting Samsung devices:
googleprojectzero.blogspot.com/2025/12/a-lo...
loading . . .
A look at an Android ITW DNG exploit
Posted by BenoĂŽt Sevens, Google Threat Intelligence Group Introduction Between July 2024 and February 2025, 6 suspicious image files were ...
https://googleprojectzero.blogspot.com/2025/12/a-look-at-android-itw-dng-exploit.html
about 1 month ago
1
7
5
Crime show: âWe know the victim died at night because we found beef in his stomach.â Me, shoving a left-over burger in my face at 7am: đŤ˘
about 1 month ago
2
4
0
Your phoneâs more likely to hit the ASLR state you need if you put a lucky dragon on it
about 2 months ago
0
3
0
I love how my city sends me text message alerts when thereâs the chance to see a sinkhole
about 2 months ago
0
0
0
New Blog Post: Seth Jenkins broke kASLR by doing ⌠nothing đŠ
googleprojectzero.blogspot.com/2025/11/defe...
loading . . .
Defeating KASLR by Doing Nothing at All
Posted by Seth Jenkins, Project Zero Introduction I've recently been researching Pixel kernel exploitation and as part of this research I ...
https://googleprojectzero.blogspot.com/2025/11/defeating-kaslr-by-doing-nothing-at-all.html
3 months ago
0
10
5
Serious bugs often occur in third-party components integrated by other software. Ivan Fratric and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click.
project-zero.issues.chromium.org/issues/42807...
loading . . .
Project Zero
https://project-zero.issues.chromium.org/issues/428075495
3 months ago
1
10
1
Super cool potential ASLR leak involving dictionary hashes!
googleprojectzero.blogspot.com/2025/09/poin...
loading . . .
Pointer leaks through pointer-keyed data structures
Posted by Jann Horn, Google Project Zero Introduction Some time in 2024, during a Project Zero team discussion, we were talking about how...
https://googleprojectzero.blogspot.com/2025/09/pointer-leaks-through-pointer-keyed.html
4 months ago
0
10
6
fseek and you shall lfind
4 months ago
0
1
0
reposted by
Natalie Silvanovich
Lorenzo Franceschi-Bicchierai
5 months ago
Zero-day developer and seller Exodus casually brags in a blog post about having found a WebKit zero-day and sold it for a year and a half.
blog.exodusintel.com/2025/08/04/o...
ClĂŠment Lecigne and BenoĂŽt Sevens of Google's Threat Analysis Group were the ones that reported it to Apple.
1
21
10
Left blue, right red
#defcon
5 months ago
0
3
0
How to use your Defcon badge
5 months ago
1
4
1
âYou wouldnât happen to have anything that could help me understand todayâs ever-changing threat landscape? Perhaps involving a bit of AI?â
6 months ago
0
3
1
Peak BH slide
6 months ago
0
1
0
Do you ever feel like maybe you should sign something, but arenât quite sure you can follow through?
6 months ago
0
4
0
We also posted our first Transparency Report
googleprojectzero.blogspot.com/p/reporting-...
loading . . .
Reporting Transparency
As part of our 2025 Policy Trial , Project Zero will use this page to publicly track our Reporting Transparency effort. The trial commenced ...
https://googleprojectzero.blogspot.com/p/reporting-transparency.html
6 months ago
0
3
1
While most vendors ship timely patches for vulnerabilities reported by Project Zero, they donât always reach users. Today, weâre announcing Reporting Transparency, a new policy to encourage downstream fixes
googleprojectzero.blogspot.com/2025/07/repo...
loading . . .
Policy and Disclosure: 2025 Edition
Posted by Tim Willis, Google Project Zero In 2021, we updated our vulnerability disclosure policy to the current "90+30" model. Our goals we...
https://googleprojectzero.blogspot.com/2025/07/reporting-transparency.html
6 months ago
1
6
9
reposted by
Natalie Silvanovich
Microplastics Sommelier
6 months ago
maybe there's still some good left in this world after all
loading . . .
312
17336
4931
The new Tamagotchi Switch game has rap battles where the Tamas rap about how they respect and enjoy each othersâ unique differences
6 months ago
0
3
0
reposted by
Natalie Silvanovich
lukelukeluke
7 months ago
Inventor of the GIF, hearing about Notre Dame burning: oh no the jarjoyles
72
5314
1250
reposted by
Natalie Silvanovich
Dr. Jen Gunter
7 months ago
I accidentally closed a browser yesterday with 72 VERY IMPORTANT TABS that have been following me around like Jacob Marley and somehow my history is not recoverable. Reader, I let them go, and have lived to tell the tale.
30
431
14
At least 3 miles of protesters along El Camino in Sunnyvale
7 months ago
1
6
0
I Googled âhow to shorten a chain,â and got no good answers, so hereâs the answer, hereâs how you temporarily shorten it
7 months ago
0
1
0
reposted by
Natalie Silvanovich
Pookleblinky
8 months ago
www.ibiblio.org/harris/500mi...
You might be one of the lucky people to learn today about an emailing bug that turned out to be caused by the speed of light.
loading . . .
The case of the 500-mile email
https://www.ibiblio.org/harris/500milemail.html
2
43
16
If thereâs one thing Iâve learned, itâs that tab completion is never âjust broken todayâ
8 months ago
0
0
0
8 months ago
0
2
0
If $106,050.10 was the size of a quarter, it would fit in 424,200.4 fewer shipping containers than âŚ
8 months ago
0
0
0
The world never says hello back
8 months ago
2
8
2
The final part of Mateuszâs Windows Registry series is live! Contains all the hive memory corruption exploitation youâve been waiting for
googleprojectzero.blogspot.com/2025/05/the-...
loading . . .
The Windows Registry Adventure #8: Practical exploitation of hive memory corruption
Posted by Mateusz Jurczyk, Google Project Zero In the previous blog post , we focused on the general security analysis of the registry a...
https://googleprojectzero.blogspot.com/2025/05/the-windows-registry-adventure-8-exploitation.html
8 months ago
0
6
4
reposted by
Natalie Silvanovich
DistrictCon
8 months ago
đ¨ CALLING ALL VULNERABILITY RESEARCHERS đ¨ The Junkyard is officially open! This is our live, on-stage pwnathon dedicated to end-of-life systems. Submit your bugs! Prizes range from $100 to $5,000 for categories like: âď¸ Most Impactful System đž Best Meme Target đ Most Engaging Presentation
1
20
18
Movie you've watched more than 1000 times using gifs. ("Hard mode" no Star Wars, Star Trek, or LoTR)
add a skeleton here at some point
9 months ago
0
1
0
Should be a Canada goose
9 months ago
0
2
0
reposted by
Natalie Silvanovich
RE//verse
10 months ago
Another must-watch talk from RE//verse 2025 is live! Zion Basque challenges decompilers to step up their game and introduces a roadmap for a practical solution to solve some of the trickiest compiler behavior's to analyze. Check it out here:
loading . . .
RE//verse 2025: Buccaneers of the Binary (Zion Basque)
Full Title: Buccaneers of the Binary: Plundering Compiler Optimizations for Decompilation Treasure. Zion's talk is both a challenge for decompilers to step up ...
https://youtu.be/VP29biKLoSw
0
7
2
10 months ago
1
5
0
Comment 6: I donât know, ask Past Natalie
11 months ago
0
4
0
reposted by
Natalie Silvanovich
Wes Miller
11 months ago
I know, Word. "syncable" isn't a word. But the dictionary is powerless against Microsoft.
0
2
2
You wouldnât download an orange tree
11 months ago
1
4
2
Not correct, yet a strange window into my soul
12 months ago
0
0
0
reposted by
Natalie Silvanovich
Alt National Park Service
12 months ago
542
60015
14038
reposted by
Natalie Silvanovich
evacide
12 months ago
tl;dr WhatsApp fixed the vuln on the back end, so you don't need to do anything to your phone, up to and including enabling Lockdown mode. Paragon Solutions sucks and you should be mad at them for enabling spying on civil society.
www.theguardian.com/technology/2...
loading . . .
WhatsApp says journalists and civil society members were targets of Israeli spyware
Messaging app said it had âhigh confidenceâ some users were targeted and âpossibly compromisedâ by Paragon Solutions spyware
https://www.theguardian.com/technology/2025/jan/31/whatsapp-israel-spyware
3
123
49
reposted by
Natalie Silvanovich
James Forshaw
12 months ago
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process.
googleprojectzero.blogspot.com/2025/01/wind...
loading . . .
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
https://googleprojectzero.blogspot.com/2025/01/windows-bug-class-accessing-trapped-com.html
2
65
41
reposted by
Natalie Silvanovich
Azeria
about 1 year ago
Killer lineup! Canât wait to attend. If you are into reverse engineering, check out the new Re-Verse conference, launching in February! The team behind it is incredible. This is going to be the new Infiltrate.
add a skeleton here at some point
0
13
4
reposted by
Natalie Silvanovich
RE//verse
about 1 year ago
We're pleased to announce Natalie Silvanovich
@natashenka.bsky.social
as the keynote speaker for the inaugural RE//verse. She might have started out hacking Tamagotchis, but she certainly didn't stop there!
1
17
9
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click
project-zero.issues.chromium.org/issues/36869...
loading . . .
Project Zero
https://project-zero.issues.chromium.org/issues/368695689
about 1 year ago
1
38
18
reposted by
Natalie Silvanovich
Steve Klabnik
about 1 year ago
WARNING: This product contains programming languages known to the State of California to cause memory unsafety
61
3469
258
Load more
feeds!
log in