V4bel's banner
V4bel's profile picture

V4bel

@v4bel3,937 subscribers

Independent Vuln. Researcher / Pwn2Own Berlin 2025, 2026 / Google kernelCTF 0-day / Google kvmCTF 0-day / Pwnie Awards 2025, 2026

Shorts

💥 Introducing "Zapscape" (CVE-2026-64561) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU's recursive "ZAP" path. Can escape to the host on x86 public clouds that expose nested virtualization. A separate vulnerability from Januscape. If you match the vulnerable conditions, apply the patch immediately. Details:

💥 Introducing "Zapscape" (CVE-2026-64561) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU's recursive "ZAP" path. Can escape to the host on x86 public clouds that expose nested virtualization. A separate vulnerability from Januscape. If you match the vulnerable conditions, apply the patch immediately. Details:

30,890 просмотров

qwerty and I exploited a VSock 1-day in Google kernelCTF back in *February*, securing $71,337 🥳 (CVE-2025-21756, exp237/exp249) And I’ve just published the write-up: A kernel developer reviewing a patch for a separate VSock bug I submitted accidentally discovered this vulnerability, and we were the first to exploit it. PoC 💻: root on Ubuntu 24.04

qwerty and I exploited a VSock 1-day in Google kernelCTF back in *February*, securing $71,337 🥳 (CVE-2025-21756, exp237/exp249) And I’ve just published the write-up: A kernel developer reviewing a patch for a separate VSock bug I submitted accidentally discovered this vulnerability, and we were the first to exploit it. PoC 💻: root on Ubuntu 24.04

15,887 просмотров

Videos

Больше нет контента для загрузки