Zooming in on Zero-Click Exploits
googleprojectzero.blogspot.com
googleprojectzero.blogspot.com
Hmm, not entirely sure I would agree. ASLR can help, sure, but ASLR isn't really that great in the context of other bugs (I guess this could be reworded as "it costs you one extra bug"). That said, Zoom should absolutely be using it, since it's so cheap.
ASLR is the the important exploit mitigation technique I can think of.
- Just-In-Time Compiler
- - JavaScript, in certain mode
- - .NET (Microsoft C# compiler)
- - Java Virtual Machine (JVM)
- - Adobe ActionScript (embedded JavaScript)
- Berkeley Packet Filter (Linux) API
- Adobe Actionscript (Adobe Flash)
As a security architect, you should be extremely mindful of the immense baggage that JIT design comes with.
References
Unfortunately they (and Teams) are making this harder and harder.
I did learn that backends of Zoom are made up of PHP, JavaScript (both server-sid and client-side), Python, CSS, and HTML.