Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Natalie Silvanovich

@natashenka@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Tamagotchi hacker. Google Project Zero. she/her

1133 Followers
129 Following
32 Posts
Joined December 14, 2022
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 1mo ago

Project Zero is hiring!

https://goo.gle/3UMXQIZ

Please share with anyone you think would be great for the role.

Staff Security Engineer, Security Research
goo.gle

Staff Security Engineer, Security Research

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities. There's no such thing as a safe system, only safer systems. Our Security team works to create and maintain the safest operating environment for Google's

23
1
30
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 1mo ago

Weekend project

10
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 1mo ago

For all the uncertainty they cause, LLMs are pretty terrible at creating slides of question marks doing the conga

7
0
2
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago

The passage of time is relentless

12
0
2
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago

What if Python smelled the flowers? Read a book? Did anything but complain about consistent use of tabs and spaces?

16
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 4mo ago

Seth Jenkins updated our 0-click exploit chain to work on a Pixel 10 with an eye-popping driver bug!

We’ll be presenting this work Saturday @offensive_con@bird.makeup

https://projectzero.google/2026/05/pixel-10-exploit.html

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
projectzero.google

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible t...

32
0
8
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago

You are the manager of a vulnerability research team. You are easily distracted and often late for meetings. You forget important emails.

8
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 3mo ago
New variation on an old theme: reporting a low severity bug because AI *fixates* on it to the exclusion of other bugs
11
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Remarkably, iOS also integrates the UDC in a 1-click context, but this bug is not exploitable, because the codec is compiled with -fbounds-safety, which inserted bounds checking instructions, making the bug unreachable.
47
10
19
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago
When you join the Stonecutters, you get the real H264 conformance test vectors, that really test all the features
4
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
The first bug in the chain is CVE-2025-54957, a memory corruption bug in the Dolby Unified Decoder, an audio codec integrated by most Android devices’ OEMs. It is 0-click because incoming SMS and RCS audio messages are automatically transcribed by the system.
34
14
14
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 3mo ago

Some of us don’t snitch, alright?

https://www.calparks.org/press/californians-urged-observe-and-report-monarch-butterfly-sightings

Californians Urged to Observe and Report Monarch Butterfly Sightings
California State Parks Foundation

Californians Urged to Observe and Report Monarch Butterfly Sightings

7
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 5mo ago

Big changes to Android and Chrome VRP:

- focus on high-impact, reproducible bugs with low/no reward for lower impact
- big prizes for full chains with some annual limits
- PoCs required

It’s the end of an era, but the start of a new one.

https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era

Blog: Evolving the Android & Chrome VRPs for the AI Era
bughunters.google.com

Blog: Evolving the Android & Chrome VRPs for the AI Era

We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of reports and bug categories that provide the most value to security today.

13
0
8
1
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
IMO, the biggest takeaway from this research is the huge promise shown by memory mitigations, both hardware and software, in protecting users against 0-days.
20
1
9
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 7mo ago

Ivan Fratric shares some tips and tricks for grammar fuzzing

https://projectzero.google/2026/03/mutational-grammar-fuzzing.html

On the Effectiveness of Mutational Grammar Fuzzing
projectzero.google

On the Effectiveness of Mutational Grammar Fuzzing

Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar t...

13
1
9
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 6mo ago

Just put a reminder in my calendar for November 1, 2026 to check whether we still have bugs

10
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
IMO, the biggest takeaway from this research is the huge promise shown by memory mitigations, both hardware and software, in protecting users against 0-days.
17
0
3
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 4mo ago

And the Owl said, “If you want to find the maintainer, go to the north side of the pond when the moon is out. Turn yourself around three times, then look into the water to see them.”

5
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago

Our intrepid 20%-er @dillonfranke@infosec.exchange exploited a vulnerability in CoreAudio. See his process for gaining privilege escalation on a Mac:

https://projectzero.google/2026/01/sound-barrier-2.html

projectzero.google
14
0
7
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
The second bug, CVE-2025-36934, is a driver UaF which only affects the Pixel 9, but Project Zero has found many other bugs with similar impact affecting other devices over the past couple years.
14
1
4
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Make sure to check out the full series here: https://projectzero.google/2026/01/pixel-0-click-part-1.html
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
projectzero.google

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Over the past few years, several AI-powered features have been added to mobile phones that allow ...

13
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 7mo ago
9
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Attack surface reduction is also important— the UDC is largely used by commercial media like TV shows, most devices don’t even have an encoder. Does it really need to be 0-click?
12
3
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 8mo ago
Replying to
Supply-chain issues also played a role: both vulnerabilities were patched very slowly, due to a variety of factors including bug prioritization, licensing and communication between vendors.
9
1
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 5mo ago

Amazing work by Meta implementing fast and robust WebRTC updates!

“We can’t push updates because …” can often be solved with investment and innovative engineering

https://engineering.fb.com/2026/04/09/developer-tools/escaping-the-fork-how-meta-modernized-webrtc-across-50-use-cases/

Escaping the Fork: How Meta Modernized WebRTC Across 50+ Use Cases
Engineering at Meta

Escaping the Fork: How Meta Modernized WebRTC Across 50+ Use Cases

At Meta, WebRTC powers real-time audio and video across various platforms. But forking a large open-source project like WebRTC within our monorepo presents unique challenges – over time, an interna…

4
0
1
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 4mo ago

There’s ‘shrinkwrap’ on this Tamagotchi … sticker

2
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 5mo ago

There’s a little piece of my heart that beats just for Spanify

https://groups.google.com/a/chromium.org/g/chromium-dev/c/iEy69ygz-rs

groups.google.com

Introducing Spanification

2
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 14mo ago
Replying to
(🔥🔥🔥)
1
0
0
0
Open post
Natalie Silvanovich @natashenka@infosec.exchange
· 2mo ago
I’ve been Palling and Malling for so long that even my Momma thinks that my mind is gone
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:58:04 UTC