Editor's Picks

Best Talks at OffensiveCon 2026

Hand-picked from in-depth reviewer verdicts — the top 6 talks from this conference. Skip the noise, find the signal.

← All talks at OffensiveCon 2026

  1. 1

    A 0-Click Exploit Chain For The Pixel 10

    Natalie Silvanovich, Seth Jenkins

    This talk, presented by Google Project Zero researchers Natalie Silvanovich and Seth Jenkins, details a sophisticated **zero-click exploit chain** targeting Google Pixel 9 and Pixel 10 devices. The primary objective was to achieve root access on these modern Android phones with…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway MUST SEE ★★★★★
  2. 2

    Tile-Based Deferred Rooting: When Your GPU Starts Rendering To Kernel Code Space!

    Xingyu Jin, Martijn Bogaard

    This talk, presented by Xingyu Jin and Martijn Bogaard, delves into a fascinating and unconventional GPU hardware vulnerability discovered during the development of the Google Pixel 10. The researchers, part of the Android threat team, uncovered a critical flaw in the…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway STRONG ACCEPT ★★★★☆
  3. 3

    Enhanced Insecurity Mode: 23 RCEs in Edge's "Safe" WebAssembly Interpreter

    Nan Wang (sakura), Ziling Chen (R1nd0)

    In a groundbreaking presentation at OffensiveCon, Nan Wang (sakura) and Ziling Chen (R1nd0) from Cyber Kunlun unveiled a comprehensive analysis of Microsoft Edge's "Enhanced Security Mode," revealing 23 **Remote Code Execution (RCE)** vulnerabilities within its WebAssembly…

    0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway MUST SEE ★★★★★
  4. 4

    Your TEE Is Only as Strong as Its Interconnect: Breaking SEV-SNP using AMD's Infinity Fabric

    Chris, Benedict Schlueter

    In this highly technical talk from OffensiveCon, Chris and Benedict Schlueter unveiled two novel attacks, "Fabric" and "Breakfast," that fundamentally undermine the security guarantees of AMD's **Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP)**. Their research…

    0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway MUST SEE ★★★★★
  5. 5

    Exploiting QSEE Vulnerabilities In Google's Wifi Pro

    Cristofaro Mune

    This talk, "Exploiting QSEE Vulnerabilities In Google's Wifi Pro," delivered by Cristofaro Mune of Raelize, delves into critical security vulnerabilities discovered within the **Qualcomm QSEE (Qualcomm Secure Execution Environment)** implementation on the Google Nest Wi-Fi Pro…

    0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway SOLID ★★★☆☆
  6. 6

    From Zero To Root: Attacking Qualcomm DSP Driver

    Xiling Gong

    This talk by Xiling Gong from Tencent Blade Team delves into a critical vulnerability (CVE-2023-47394) found within the second generation of Qualcomm's **FastRPC** driver, a core component responsible for interfacing with the **Audio/Application Digital Signal Processor…

    0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway STRONG ACCEPT ★★★★☆