Authored by James Forshaw, Google Security Research

The WSAQuerySocketSecurity API returns full anonymous impersonation tokens for connected peers in an AppContainer leading to a sandbox escape.

advisories | CVE-2021-40476