
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Varik&#39;s Blog</title>
      <link>https://varik.dev/blog</link>
      <description>Varik&#39;s blog</description>
      <language>en-us</language>
      <managingEditor>varikmatevosyan@gmail.com (Varik Matevosyan)</managingEditor>
      <webMaster>varikmatevosyan@gmail.com (Varik Matevosyan)</webMaster>
      <lastBuildDate>Fri, 19 Jun 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://varik.dev/tags/jsc/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://varik.dev/blog/jsc/jsc-exploitation-primitives-part-1</guid>
    <title>JSC Exploitation Primitives - Part 1: From One OOB to Cage-Free Arbitrary R/W</title>
    <link>https://varik.dev/blog/jsc/jsc-exploitation-primitives-part-1</link>
    <description>Coming from V8 and landing in JavaScriptCore. Building the addrof/fakeobj/read64/write64 ladder from a single out-of-bounds write, and the JSC-specific walls (the gigacage, butterflies, NaN-boxing) that make the last step harder than it is in V8.</description>
    <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
    <author>varikmatevosyan@gmail.com (Varik Matevosyan)</author>
    <category>PWN</category><category>JSC</category><category>JavaScriptCore</category><category>WebKit</category><category>Safari</category><category>Browser Exploitation</category>
  </item>

    </channel>
  </rss>
