Quang L

Painting Out of the Box: Escaping the Chrome Renderer Sandbox via Skia

Abstract

This talk presents a Chrome Stable M146 renderer-to-GPU-process sandbox escape on Linux, built from a Skia integer overflow and a memory leak that works by rendering memory as pixels.

The unusual part is the read primitive. Instead of leaking memory through a normal API, the exploit points SkPathData at chosen GPU-process memory and asks Skia to draw it. The bytes at that address are interpreted as floating-point coordinates, rasterized onto a canvas, and copied back to the renderer as pixels.

We use clever algorithms and float math to recover the information from the rendered pixel with high fidelity.

This talks will cover what it takes to escape Chrome renderer sandbox from "not-so-powerful" bugs.

BIO

Quang Luong is a researcher at Calif.io. He started out as a systems engineer before turning into hacker.