Hacker News new | ask | show | jobs
by mrbluecoat 18 days ago
Seems low considering the wide impact, but maybe the only thing corporations throw big money at is remote exploits?
2 comments

That's a huge amount of money for a vulnerability.
Also one order of magnitude less than you could get on the black market for a universal Linux LPE and two orders less if you can make it work reliably.
I believe you are two orders of magnitude wrong, in the upward direction, on that number (the first of them). You're talking about reliable remote numbers there, full chain, full enablement, tranched with maintenance.
Surely working on Android adjusts the number upwards by a lot?
How is it a wide impact?

It requires being able to execute arbitrary code on the machine in userspace. If you have that, most of the time you don't even care about kernel level exploits.

It's a browser to kernel full chain exploit, from url click to root your device.
No, GhostLock is not browser to Kernel.

https://nebusec.ai/research/v8-maglev-incorrect-phis-untaggi...

This is the browser part.

> Step1. Download Vulnerable Firefox.

Please tell me you are trolling me and not this stupid.

I think you are misunderstanding the objective.
Supposedly it can root Android.