Chrome’s Crashpad handler runs outside the renderer sandbox, yet a compromised renderer can request a crash dump and supply much of the state that the handler processes. This creates an unusual trust boundary and a viable sandbox-escape surface. I will present two vulnerabilities in Crashpad, along with a working exploit that chains them together to escape the renderer sandbox. Although both bugs provided highly constrained primitives that initially appeared impossible to exploit on their own, I will show how those constraints were overcome to build a reliable exploit that achieved code execution in the Crashpad handler
Andrés Luksenberg has been an enthusiast of exploit writing and related things for longer than he can remember, which probably reveals more about his age than he would like to admit. He also hates talking about himself in the third person.
He has worked at several companies as a security researcher and exploit writer. He currently works at XBOW, where he keeps trying to break software and develop exploits, now with LLMs as part of the process.