EXODUS BLOG


Exploit Techniques

Dnsmasq DNS Remote Heap Buffer Overflow

JULY 20, 2026
By David Barksdale In this blog post, we discuss a heap buffer overflow vulnerability that we found in Dnsmasq. This vulnerability was fixed in version 2.92rel2 and 2.93 on 11 May 2026 and assigned CVE-2026-2291. We...
Read More

Oops Safari, I think You Spilled Something!

AUGUST 4, 2025
Overview In February 2023, researchers at Exodus Intelligence discovered a bug in the Data Flow Graph (DFG) compiler of WebKit, the browser engine used by Safari. This bug, CVE-2024-44308, was patched by Apple in...
Read More

Windows Sockets: From Registered I/O to SYSTEM Privileges

DECEMBER 2, 2024
By Luca Ginex Overview This post discusses CVE-2024-38193, a use-after-free vulnerability in the afd.sys Windows driver. Specifically, the vulnerability is in the Registered I/O extension for Windows sockets. The vulnerability was patched in the...
Read More