Exploiting Chrome on a Nexus Phone

Author: Guang Gong

The speaker will tell how to pwn a Nexus device with a single vulnerability. He will also talk about how to get an RCE permission by using a V8 vulnerability and then demonstrate breaking Chrome's sandbox without exploiting any security flaws.

Guang Gong is a security researcher of the Mobile Safe Team of Qihoo 360. His research interests included Windows rootkits, virtualization and cloud computing. He is currently focuses on mobile security, especially on hunting and exploiting Android’s vulnerabilities. He has spoken at several security conferences such as Black Hat, CanSecWest, PacSec, SysCan360. He is the winner of Pwn2Own 2015, Pwn0Rama 2016 (the category of mobile devices), and Pwn2Own 2016 (the target: Chrome).

