Skip to navigation Skip to main content Skip to footer

Gone in 60 Frames – USB Video Exploitation (DEF CON 34)

By Alex Plaskett

24 August 2026

Alex Plaskett and Robert Herrera presented “Gone in 60 Frames – USB Video Exploitation” on the 9th of August 2026 at DEF CON 34 Las Vegas.  

Video

Slides 

https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Alex%20Plaskett%2C%20Robert%20Herrera%20-%20Gone%20in%2060%20Frames%20-%20USB%20Video%20Exploitation%20-%20In60%20Slides%20v1.pdf

Whitepaper 

https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Alex%20Plaskett%2C%20Robert%20Herrera%20-%20Gone%20in%2060%20Frames%20-%20USB%20Video%20Exploitation%20-%20In60%20Whitepaper%20v1.pdf

Abstract 

The abstract for the talk presented was as follows: 

In 2025, Amnesty International, in collaboration with Google TAG, released a write-up of an in-the-wild chain of USB Linux kernel vulnerabilities which was used to compromise mobile devices. 

Whilst the vulnerabilities themselves were disclosed, no details on how these vulnerabilities could be exploited were provided. This led us to deep dive into these issues to determine how they could be leveraged for arbitrary code execution. 

This is the story of exploiting one of these vulnerabilities (CVE-2024-53104), an out of bounds write in USB Video which offered a brilliant exploit primitive leading to highly reliable code execution when chained together with an information leakage vulnerability. 

In this talk we will first discuss the in-the-wild vulnerabilities, moving on to providing background of USB specifics for several device classes and coverage guided fuzzing for finding new issues. 

We will then move onto a more recent information disclosure vulnerability CVE-2025-38494 which could be leveraged to bypass KASLR. 

An extensive deep dive into CVE-2024-53104 vulnerability will be performed (the OOB write) and we will discuss our novel technique used for exploitation of this issue and expose the power of the UVC_QUIRK_RESTRICT_FRAME_RATE quirk! 

Finally, we will wrap up our talk with several demonstrations.