Jann Horn - jann@infosec.exchange (@tehjh) 's Twitter Profile
Jann Horn - [email protected]

@tehjh

occasional human borrow checker; works at Google Project Zero; personal account;

mastodon: [email protected]

ID: 355089809

calendar_today14-08-2011 20:24:29

5,5K Tweet

16,16K Followers

228 Following

Ian Beer (@i41nbeer) 's Twitter Profile Photo

Mind the gap: googleprojectzero.blogspot.com/2022/11/mind-t… Part of project zero's remit is to drive structural improvements across the ecosystem.

Ian Beer (@i41nbeer) 's Twitter Profile Photo

This includes calling out failures and patch gapping is currently a major issue with Android. In this case, 5 Mali GPU vulnerabilities we reported this summer were fixed by ARM but those fixes still haven't made it to end user devices, many months later.

Seth Jenkins (@__sethjenkins) 's Twitter Profile Photo

Excited to announce my first ever P0 blogpost is now public! It details a new exploit strategy on Linux kernel that Jann and I worked together to invent. Thanks to everyone on the P0 team for giving me the opportunity to achieve this dream! googleprojectzero.blogspot.com/2022/12/exploi…

Man Yue Mo (@mmolgtm) 's Twitter Profile Photo

In this post I'll use CVE-2022-38181, a use-after-free I reported last year in the Arm Mali GPU driver to gain arbitrary kernel code execution and root from untrusted Android app. Not sure if the bug or the disclosure is more interesting: github.blog/2023-01-23-pwn…

Tim Willis (@itswillis) 's Twitter Profile Photo

What happens when you get Natalie Silvanovich, Ivan Fratric 💙💛, Felix Wilhelm, Ian Beer and Jann Horn - [email protected] working collaboratively on a new attack surface for the team? This: googleprojectzero.blogspot.com/2023/03/multip… The blogpost also includes actions that users can take to protect themselves while waiting for patches.

Tavis Ormandy (@taviso) 's Twitter Profile Photo

First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! lock.cmpxchg8b.com/zenbleed.html