Hugo
Security researcher with strong interest in Windows internals, RE tooling and automation. Previously spent two years at the French Ministry of Defense on vulnerability research and RE tooling. Currently works at Konvu on automated vulnerability triage. Lectures on cybersecurity at French engineering schools.
Session
Prism is Microsoft's binary translator on Windows on ARM, JIT-compiling x86 and x64 to ARM64 at runtime. Five binaries, ~11K functions, no symbols. We reversed the full JIT pipeline, the CHPE/ARM64X hybrid loading mechanism, and the undocumented .jc translation cache format. Along the way we found that the x64se variant runs CRC32C integrity verification on translated code while x86 does not. The cache has no integrity checks on x86 translations: four structural checks, then arbitrary ARM64 executes verbatim. We release prism-cache-parser and demonstrate cache poisoning on Snapdragon X: drop a crafted .jc file, hijack translations for any DLL, survive reboots, invisible to every default detection layer.
