Enhanced Insecurity Mode: 23 RCEs in Edge's "Safe" WebAssembly Interpreter

Nan Wang (sakura), Ziling Chen (R1nd0)

OffensiveCon 2026 · Day 1 · Main Stage

In a groundbreaking presentation at OffensiveCon, Nan Wang (sakura) and Ziling Chen (R1nd0) from Cyber Kunlun unveiled a comprehensive analysis of Microsoft Edge's "Enhanced Security Mode," revealing 23 **Remote Code Execution (RCE)** vulnerabilities within its WebAssembly interpreter, **Dropbear**. This research highlights a critical paradox: a security feature designed to protect users by disabling **Just-In-Time (JIT)** compilation inadvertently introduced a significant new attack surface. The talk meticulously detailed how a pure software interpreter, intended to run WebAssembly in a hardened environment, became a fertile ground for high-impact security flaws.

AI review

Wang and Chen didn't just find bugs — they found 23 RCEs in a component Microsoft introduced specifically to make the browser more secure, then built a universal exploit chain on top of them. This is the rare talk where the premise, the technical execution, and the defensive implications all land at the same level: elite.

Watch on YouTube