Pwno

Pwno is a AI cybersecurity startup founded by two high-schoolers. It competes directly with Google Deepmind on the world's hardest cybersecurity problem: memory security. We find big, scary bugs in critical systems with AI.
We had been working on this question for around 8 months, from initaily just trying to harness gdb.

What we did

Here's a list of bugs we found,
and currently patched.

PROJECTCOMPONENTIDTYPEDATE
RedisPWNO-0019[REDACTED][REDACTED]2025-12-30
RedisPWNO-0018[REDACTED][REDACTED]2025-12-30
RedisPWNO-0017[REDACTED][REDACTED]2025-12-30
ChromiumPWNO-0015UAF read in WebDragDest::dropHitTestDidComplete invalid-drag-target path on macOSUAF2025-12-23
FFmpegPWNO-0014Heap-buffer-overflow in EXIF writer for extra IFD tagsOOB Write2025-12-21
Dng-sdkPWNO-0013[REDACTED]Unitialized memory2025-12-19
WebKitPWNO-0012[REDACTED][REDACTED]2025-12-18
WebKitPWNO-0011[REDACTED][REDACTED]2025-12-18
OpenSSLPWNO-0010OOB write in SHA3/KECCAK deserializationOOB Write2025-12-16
OpenSSLPWNO-0009OOB write via SHA-2 digest deserializationOOB Write2025-12-16
FFmpegPWNO-0008Heap OOB write in libsvtjpegxs decoder, chunk modeOOB Write2025-12-14
FFmpegPWNO-0007Heap OOB write in MPEG-TS JPEG‑XS PES parsing (libavformat/mpegts.c)OOB Write2025-12-14
FirefoxPWNO-0006UAF in nsDocLoader::GetInterface during APZ repaint / scrollingUAF2025-12-13
FFmpegPWNO-0003avformat/sierravmd: fix header read error check (tiny precedence bug)Undefined Behavior2025-12-11
FFmpegPWNO-0005OOB read in Vulkan DPX hwaccel shader OOB Read2025-12-11
FFmpegPWNO-0002Crash in vf_noise SSE2 on misaligned frames Denial of Service2025-12-08
FFmpegPWNO-0001Stack overflow in drawvg parser on deeply nested scriptsStack Overflow2025-12-08