Program

/

CODE BLUE 2026

Time Table

In Origin We Trust: Breaking Chromium from Its Privileged Side

Browser security is hard, especially with the sharpest minds all on the same target. Years of mitigations have made a modern Chromium full chain one of the toughest exploits: a memory-corruption bug in V8 or Blink, a V8 Sandbox bypass to own the renderer, then another in Mojo IPC or the kernel to break out.

But what if we skip all that and go straight for its privileged process?

In this talk, we throw out memory-corruption bugs and take on Chromium’s security model with pure logic alone. All inside the browser process. We found ~20 logic bugs, chained into three attacks: several UXSS at once, a 0-click arbitrary file read, and the Microsoft Edge full chain from Pwn2Own 2026. We’ll cover revived and new attack surfaces, island-hopping between privileged origins, the renderer/browser trust boundary, and how AI helped.

Not all bugs are born equal: some look unexploitable, even like features. But chained the right way, even the most harmless one becomes a vital link in the great escape.

  • Location :

    • Track 1(HALL B)

  • Category :

    • Technical

  • Share :

Speakers

  • オレンジ・ツァイ の写真

    Orange Tsai

    オレンジ・ツァイ

    Orange Tsai is the principal security researcher at DEVCORE and a core member of CHROOT Security Group in Taiwan. He is also the champion and "Master of Pwn" holder at Pwn2Own Vancouver 2021, Toronto 2022, and Berlin 2026, as well as a PHRACK #72 author. Over the years, Orange has spoken at several top hacking conferences such as Black Hat USA (6 times), DEF CON (5 times), HITCON (14 times), CODE BLUE (6 times), RomHack (2 times), Hexacon, POC, HITB, and WooYun!

    ‍​

    Orange is a 0day researcher focusing on Web & App Security. His research not only earned him the Pwnie Award for "Best Server-Side Bug" in 2019 and 2021 but also secured 1st place in the "Top 10 Web Hacking Techniques" for 2017, 2018, and 2024.

    ‍​

    You can find him at @orange_8361 and https://blog.orange.tw/