When a user clicks a link in a phishing email, the browser is exploited first, gaining code execution in the browser process; modern browsers have sandboxing, but the attacker must achieve sandbox escape and then privilege escalation to reach kernel-level execution, at which point defenses on the host essentially fail

causalpending

Speaker

Matthew Holland

Evidence Quote

the first thing that happens is uh you know the browser would be exploited... it gains execution inside the browser and then the goal is then to uh gain privilege... ideally get execution in the operating systems kernel and once you're there um it's largely game over

Source

You Get Hacked When You Don't Do These Simple Things! (Don't let your life be ruined...)The Knowledge Project Podcast
Created: 8/11/2026, 1:11:07 AM

My Notes

Loading notes...