Sept. 27, 2023, 6:21 p.m. | Black Hat

Black Hat www.youtube.com

Nowadays, multiple mitigation mechanisms have gradually been added to Google Chrome in order to reduce the traditional RCE attack surfaces (e.g., V8 and Blink), which greatly increases the attack difficulty. Besides these well-known attack surfaces, we found SQLite can be directly accessed by remote attackers via Chrome WebSQL API.

In this talk, we will present a mutation-based Fuzzer towards WebSQL....

By: Ziling Chen , Hongli Han , Nan Wang

Full Abstract & Presentation Materials:
https://www.blackhat.com/asia-23/briefings/schedule/#new-wine-in-an-old-bottle-attacking-chrome-websql-30653

api attack attackers attack surfaces blink chrome found google google chrome mitigation old order rce sqlite well-known wine

Senior Security Officer

@ eSimplicity | Remote

Senior - Automated Cyber Attack Engineer

@ Deloitte | Madrid, España

Public Key Infrastructure (PKI) Senior Engineer

@ Sherwin-Williams | Cleveland, OH, United States

Consultant, Technology Consulting, Cyber Security - Privacy (Senior) (Multiple Positions) (1502793)

@ EY | Chicago, IL, US, 60606

Principal Associate, CSOC Analyst

@ Capital One | McLean, VA

Real Estate Portfolio & Corporate Security Lead

@ Lilium | Munich