
Proof-of-concept remote code execution exploit targeting Safari 11.0.3 on macOS 10.13.3 via a WebAssembly section vulnerability (CVE-2018-4121). Includes heap spray and dylib payload integration.
by MWR Labs (c) 2018
python file_to_jsarray.py your.dylib payload.js