Cybersecurity Researcher Mohan Pedhapati Met als gevolg dat de beschikbaarheid van IPv4 verder vermindert., explained how he used the AI model Anthropic Claude Opus 4.6 to write a complete exploit chain for hacking the JavaScript V8 engine in Google Chrome 138, on which the current Discord client operates.

The process of writing the exploit chain took a week, the researcher reported — during this, 2.3 billion tokens were consumed and $2283 was spent for access to the AI model via API; he also contributed his own efforts, spending a total of 20 hours solving deadlock issues. The total cost of creating the hacking scheme seems significant for an individual, Mohan Pedhapati acknowledged; on the other hand, without external help, a person would have worked on a similar project for several weeks. The project turned out to be profitable economically — the reward from Google and Discord for reporting such an exploit could be around $15,000. And this is just the legal market — cybercriminals could pay different amounts for zero-day vulnerabilities.
Many services release their applications on the Electron framework, which, in turn, is based on Chrome — this is done not only in Discord, but also, for example, in Slack. However, the current code of the framework lags one version behind the browser, and application developers do not always promptly update dependencies, and users do not always install the latest versions of applications. The Discord client chosen by the researcher works on Chrome 138, which means it lags nine major versions behind the current browser version.
Elke beginnende programmeur kan, aldus Mohan Pedhapati, met genoeg geduld en een API-sleutel om toegang te krijgen tot het AI-model verouderde software hacken — "het is een kwestie van tijd, geen waarschijnlijkheid". Bovendien is "elke patch in wezen een aanwijzing voor een exploit", omdat projecten met open source transparant worden ontwikkeld; corrigenda zijn vaak openbaar beschikbaar in de code nog voordat de bijgewerkte versie van het programma als geheel wordt vrijgegeven. Om applicaties tegen dergelijke aanvallen te beschermen, raadt de expert aan om aandachtiger te zijn met afhankelijkheden en snel wijzigingen aan te brengen, evenals beveiligingspatches automatisch uit te geven, zodat gebruikerssoftware niet kwetsbaar blijft als een update simpelweg vergeten wordt te installeren. Tenslotte moeten open source-projecten voorzichtig zijn bij het publiceren van gedetailleerde informatie over kwetsbaarheden.
Bron:
Bron: 3dnews.ru
