I love how WebKit is a console hacking meme. I used to work on WebKit. I remember dragging a coworker into my office one time to explain an 0day that was being exploited in the wild that was in his code. Anyway I don’t have security clearance on their bugzilla anymore.
-
Show this thread
-
It’s true that WebKit is buggy and a pile of UaFs, but in all honesty I don’t think it has a higher-than-average bug density. It’s just…really big, and that adds up. And it’s everywhere, so it’s a convenient target.
3 replies 0 retweets 8 likesShow this thread -
Replying to @endrift
Yeah, and the places that make for the juiciest targets are also the places that usually don’t get timely updates.
1 reply 0 retweets 2 likes
Replying to @mistydemeo @endrift
Exactly. It's the best target because it's in all the devices with half a million dollar bug bounties which push updates quickly, and then it's in all the consoles running year-old versions. You can literally just pick a recent bug from a hat and use it.
11:14 PM - 8 Feb 2018
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.