RC RANDOM CHAOS

parser security

2 posts

SIGGRAPH 2023 shipped an unfuzzed ingest path
Article

SIGGRAPH 2023 shipped an unfuzzed ingest path

Gaussian splats don't break browser memory protection. Their untrusted parsers do: integer overflow to OOB write in splat viewers, CWE-190 into CWE-787.

Zero-click chains broke the user-in-the-loop model
Article

Zero-click chains broke the user-in-the-loop model

Zero-click malware does not need user action. It needs a reachable parser. What fails, why it fails, and what must be true.