OffensiveCon 2026
OffensiveCon 2026 is the premier elite offensive security research conference in Berlin. Browser exploits, kernel vulnerabilities, hardware attacks, and 0-click exploit chains — no vendor pitches, no fluff. Held May 15-16, 2026 at the Maritim Hotel Berlin.
→ See editor’s top picks at OffensiveCon 2026
- Keynote: Chaotic Good and Chaotic Bad — Ensuring Collective Success in Defensive Endeavours Through Offence — Ollie Whitehouse
Ollie Whitehouse, CTO of the UK's National Cyber Security Centre (NCSC), delivered a compelling keynote address at OffensiveCon, challenging conventional notions of cybersecurity. Titled "Chaotic…
- Tile-Based Deferred Rooting: When Your GPU Starts Rendering To Kernel Code Space! — Xingyu Jin, Martijn Bogaard
This talk, presented by Xingyu Jin and Martijn Bogaard, delves into a fascinating and unconventional GPU hardware vulnerability discovered during the development of the Google Pixel 10. The…
- Exploiting QSEE Vulnerabilities In Google's Wifi Pro — Cristofaro Mune
This talk, "Exploiting QSEE Vulnerabilities In Google's Wifi Pro," delivered by Cristofaro Mune of Raelize, delves into critical security vulnerabilities discovered within the **Qualcomm QSEE…
- 4-Byte Heap Overflow To RCE In Minecraft — Hrvoje Misetic
This talk, presented by Hrvoje Misetic at OffensiveCon, delves into the intricate process of achieving remote code execution (RCE) in Minecraft's Bedrock Edition through a 4-byte heap overflow…
- Enhanced Insecurity Mode: 23 RCEs in Edge's "Safe" WebAssembly Interpreter — Nan Wang (sakura), Ziling Chen (R1nd0)
In a groundbreaking presentation at OffensiveCon, Nan Wang (sakura) and Ziling Chen (R1nd0) from Cyber Kunlun unveiled a comprehensive analysis of Microsoft Edge's "Enhanced Security Mode,"…
- Navigating the MTE Landscape: iOS Memory Protection Deep Dive — Atlan Pinabel, Patrick Ventuzelo
This talk, presented by Atlan Pinabel of Fuzzinglabs (with co-author Patrick Ventuzelo), offers a deep dive into **Memory Tagging Extension (MTE)** as implemented within Apple's iOS ecosystem…
- A 0-Click Exploit Chain For The Pixel 10 — Natalie Silvanovich, Seth Jenkins
This talk, presented by Google Project Zero researchers Natalie Silvanovich and Seth Jenkins, details a sophisticated **zero-click exploit chain** targeting Google Pixel 9 and Pixel 10 devices. The…
- From Zero To Root: Attacking Qualcomm DSP Driver — Xiling Gong
This talk by Xiling Gong from Tencent Blade Team delves into a critical vulnerability (CVE-2023-47394) found within the second generation of Qualcomm's **FastRPC** driver, a core component…
- The DNG Weird Machine: Deconstructing an In-The-Wild Android Image Exploit — Benoît Sevens
This talk by Benoît Sevens from Google's Threat Analysis Group (now Google Threat Intelligence Group or GTIG) delves into a sophisticated in-the-wild Android exploit targeting the Digital Negative…
- Your TEE Is Only as Strong as Its Interconnect: Breaking SEV-SNP using AMD's Infinity Fabric — Chris, Benedict Schlueter
In this highly technical talk from OffensiveCon, Chris and Benedict Schlueter unveiled two novel attacks, "Fabric" and "Breakfast," that fundamentally undermine the security guarantees of AMD's…
- Pedal to the Metal: Accelerating to the Host via VirtualBox VMSVGA — NiNi Chen, Wei Che Kao (Xiaobye)
In this compelling talk from OffensiveCon, DEVCORE security researchers NiNi Chen and Wei Che Kao (Xiaobai) pull back the curtain on a treasure trove of vulnerabilities discovered within…
- Beyond the Limits of Site Isolation — Ivan Fratric
In this talk, Ivan Fratric, a seasoned security researcher and Tech Lead at Google Project Zero, delves into the often-misunderstood boundaries of **Site Isolation**, a critical security mitigation…
- IRON GIANT: When The Vault Becomes The Victim — Erik Egsgard
In the realm of Windows security, the Local Security Authority Subsystem Service, or **LSASS**, stands as a formidable guardian, often dubbed the "Iron Giant" for its critical role in managing…
- From Samsung Account to RCE: A Journey to a Remote 0-Click Capability — Kaufi
In this compelling talk at OffensiveCon, Yuval Kaufman, known as Kalfy, a VP R&D at Radiant Research Labs, detailed an intricate journey culminating in a **remote zero-click capability** leading to…
- Design-Based Vulnerabilities on macOS: Oops, Not a One-Shot Fix — Zhongquan Li
In his OffensiveCon 2026 presentation, "Design-Based Vulnerabilities on macOS: Oops, Not a One-Shot Fix," independent security researcher Zhongquan Li delved into a series of persistent and…
- Exploiting Android Apps with Counterfeit Art — Philipp Mao, Rokhaya Fall
This talk, "Exploiting Android Apps with Counterfeit Art," presented by Philipp Mao and Rokhaya Fall, delves into a novel and powerful technique for escalating file override vulnerabilities in…
- SELECT shell FROM postgres: Digging up a 20-year-old bug for ZeroDay.Cloud — Paul Gerste, Moritz Sanft
This talk, "SELECT shell FROM postgres: Digging up a 20-year-old bug for ZeroDay.Cloud," presented by Paul Gerste and Moritz Sanft, details their successful exploit of a two-decade-old vulnerability…