October 6 marks the third anniversary of v8CTF. Since launching the program, we have received and verified over 100 Chrome renderer exploits, covering every single Chrome release from M117 to today.
In this talk, the team running v8CTF looks back at what we have learned from this dataset. We will walk through how V8 exploitation evolved over the past three years: which bug classes were popular at what time, how attackers adapted to defenses like the V8 Heap Sandbox, and where people got stuck.
We will also dig into the biggest recent shift: AI. Complex browser exploitation was always considered a high bar requiring deep domain expertise. Has AI actually changed that? Is it now easy for models to turn bugs into working exploits? Do LLMs go after the same classic JIT and GC flaws humans do, or are they finding completely different bugs? Along with data from 100 exploits, we will share technical walkthroughs of some of our favorite bugs, clever primitives and sandbox bypasses submitted to the program.
Carl Smith is a Security Engineer on Google's Security Team. He previously interned at Exodus Intelligence and Google Project Zero. He is interested in fuzzing, compilers and low level research. He can be reached on twitter, mastodon or bluesky: @cffsmith / cffsmith@infosec.exchange / @rwx.page.
Stephen Rottger is interested in browser exploitation, sandboxing, CPU side channels and CTFs. Previously, member of the V8 security team.