BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026//talk//CATUNP
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-CATUNP@cfp.romhack.io
DTSTART;TZID=CET:20261003T173000
DTEND;TZID=CET:20261003T175000
DESCRIPTION:Cellular baseband processors run highly privileged\, proprietar
 y software beneath the main OS\, making them a critical yet hard-to-analyz
 e attack surface. Focusing on the Google Pixel 9 modem\, this talk demonst
 rates how adapting open-source emulation software allowed us to build a ba
 seband fuzzing pipeline\, surfacing three new vulnerabilities and several 
 rediscoveries\, including an Out-of-Bounds (OOB) read in 5G message parsin
 g.\nAfter validating the flaw with Software Defined Radios (SDRs)\, we add
 ress the challenge of turning local memory leaks into full remote attacks.
  We show how SIM Toolkit (STK) applets\, legitimate applications running o
 n SIMs/eSIMs that can be provisioned over-the-air\, can be repurposed as a
  delivery and execution primitive operating entirely outside main OS visib
 ility. Finally\, we detail how pairing remote STK provisioning with the 5G
  baseband vulnerability creates a silent\, zero-click exfiltration chain t
 hat leaks sensitive memory over SMS.
DTSTAMP:20260921T190345Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Ghost in the SIM: Silent\, Zero-Click\, Over-the-Air Exploitation o
 f a Pixel 9 Baseband OOB Read - Lorenzo Valeriani\, Pasquale Caporaso
URL:https://cfp.romhack.io/romhack-camp-2026/talk/CATUNP/
END:VEVENT
END:VCALENDAR
