Nytro Posted February 2, 2014 Report Posted February 2, 2014 Mobile Pwn2Own Autumn 2013 Chrome on Android Exploit Writeupianbeer@chromium.orgtl?drPinkie Pie exploited an integer overflow in V8 when allocating TypedArrays, abusing dlmalloc inline metadata and JIT rwx memory to get reliable code execution. Pinkie then exploited a bug in a Clipboard IPC message where a renderersupplied pointer was freed to get code execution in the browser process by spraying multiple gigabytes of sharedmemory.Download:https://docs.google.com/document/d/1tHElG04AJR5OR2Ex-m_Jsmc8S5fAbRB3s4RmTG_PFnw/edit Quote