Back to browse
CVE-2026-40369 Windows Kernel Arbitrary Write Chrome SBX

CVE-2026-40369 Windows Kernel Arbitrary Write Chrome SBX

by orinimron123·May 28, 2026·3 points·0 comments

AI Analysis

●●●●GemWizardryBig BrainRabbit Hole

100% deterministic SYSTEM escalation from Chrome sandbox via audited syscall.

Strengths
  • Single syscall achieves privilege escalation with no race conditions or heap spray.
  • Found in NtQuerySystemInformation class 253, bypassing decades of audit assumptions.
  • Full exploit developed with complete technical writeup and disclosure.
Weaknesses
  • Public disclosure without vendor patch window may accelerate weaponization.
  • Limited to Windows 11 24H2–25H2; older versions may differ.
Category
Target Audience

Security researchers, Windows kernel developers, browser security engineers

Similar To

Project Zero disclosures · ZDI advisories · Google Security Blog

Similar Projects