Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a use-after-free in FontFaceCache (https://wololo.net/2021/10/14/use-after-free-webkit-vulnerab... and https://github.com/Cryptogenic/PS5-4.03-Kernel-Exploit/blob/...), not a JIT bug.

Funnily enough, I think the CVE they're saying it is is wrong? The link to the project zero itw tracking page is for CVE-2021-30858 which is an IndexDB UAF, which is a completely seperate bug; the MITRE tracking page for CVE-2021-30858 just has the boilerplate "a malicious page can cause an exploit" from Apple, and doesn't say if it's for the IndexDB or FontFaceCache bug, so I think the Jailbreak people are just confused on this one.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: