Light

Episode #856 Quiz

The "Topics" API
Date: 2022-02-01 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

Apple patched two zero-days, including CVE-2022-22587 in IOMobileFramebuffer enabling kernel code execution, and a Safari IndexedDB cross-origin flaw exposing other tabs. Linux’s PwnKit in polkit’s pkexec mishandles argc zero, letting crafted environment variables trigger root execution; mitigations include patching or removing pkexec’s SUID bit.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: Under Google's Topics API, what determines which one of a user's top five topics is returned to a given site 95% of the time?
Question 2: What prevents a site from learning every weekly topic a browser has accumulated under the Topics API?
Question 3: In the PwnKit discussion, what specific condition did pkexec fail to check before processing startup arguments?
Question 4: What mitigation did the NSA specifically suggest if a Linux system could not be patched immediately for PwnKit?
Question 5: What was the key reason Steve gave for the smaller-than-expected wave of Log4j exploitation after Log4Shell was disclosed?
Cancel