The 2017 Pwnie Nominee For Best Client-Side Bug

One Byte Overflow and Symlinks

Credit: Anonymous

An anonymous researcher presented a chain of vulnerabilities that led to a full compromise of Google ChromeOS, starting with a single-byte overflow in the C-ARES DNS library. The path to root was complicated, weird, and beautiful.

Chrome OS exploit: One Byte Overflow and Symlinks