Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Draft:Mateusz Jurczyk

From Wikipedia, the free encyclopedia
  • Comment: In preparing this draft, I disclose that AI assistance was used as follows: This draft is a translation and adaptation of the existing Polish Wikipedia article (see the attribution in the edit summary). I used AI chatbot Google Gemini Pro to translate the text and convert the citations to English Wikipedia templates. I reviewed the final text before submitting. Bezpieczny Bezpiecznik (talk) 11:21, 4 October 2026 (UTC)

Mateusz Jurczyk
Other namej00ru
OccupationComputer security researcher
EmployerGoogle (Project Zero)
Known forDragon Sector, Bochspwn
Websitej00ru.vexillium.org

Mateusz Jurczyk, known as j00ru, is a Polish computer security specialist, a vulnerability researcher in Google's Project Zero team and a co-founder of Dragon Sector, a team competing in capture the flag (CTF) competitions.[1][2] He has received four Pwnie Awards,[1][3] and his findings include a zero-click vulnerability in Samsung smartphones that could be exploited through MMS messages.[4][5]

Career

[edit]

His work focuses on software security, including reverse engineering and vulnerability research, among others in operating system kernels. From 2009 to 2011 he worked as a security researcher and malware analyst at Hispasec Sistemas, and from 2011 to 2014 as an information security engineer at Google. He then joined the company's Project Zero team.[1]

In February 2013, together with Gynvael Coldwind and Adam Iwaniuk, he founded Dragon Sector.[2] From 2013 to 2019 the team remained in the top four of the annual CTFtime ranking,[1] and it ranked first in 2014, 2018 and 2019.[6] The team also organised its own CTF competitions, including at the CONFidence conference in Kraków in 2015–2017 and at the Security PWNing Conference in Warsaw in 2018–2019.[1]

Research

[edit]

He has reported security bugs in, among others, operating system kernel drivers, document readers, word processors, web browsers, virtual machines and antivirus software.[1]

From 2012, together with Gynvael Coldwind, he ran the fuzzing of the FFmpeg project at Google. By January 2014, 1,120 fixes for bugs they had found, some of them security-related, had been merged into FFmpeg, and 413 into its fork Libav.[7]

In 2013, together with Coldwind, he published the paper Identifying and Exploiting Windows Kernel Race Conditions via Memory Access Patterns. It described a method of detecting double fetch bugs (a type of race condition) in operating system kernels using CPU-level instrumentation. For this work both received a Pwnie Award in the "Most Innovative Research" category.[8][9] He used the Bochs emulator in the Bochspwn and Bochspwn Reloaded tools and in an infrastructure for fuzzing font handling in the Windows kernel.[10]

In 2015 he described a bug in the handling of the BLEND instruction in font rendering code shared by Adobe Reader and the 32-bit Windows kernel. It made it possible to take control of Adobe Reader through a font embedded in a PDF file and then, through the same bug in the kernel, to obtain SYSTEM privileges.[3]

In 2020 he discovered a series of bugs in the handling of the Qmage image format by the Skia graphics library on Samsung smartphones. They allowed an attacker to take control of a phone with a crafted MMS message, without any user interaction. He reported the bugs to Samsung in February 2020, and Samsung released fixes in May 2020.[4][5]

In 2022–2023 he audited the Windows Registry. He filed 39 reports, which Microsoft fixed as 44 vulnerabilities with CVE identifiers. Together with lower-severity issues reported in late 2023 and early 2024, the research resulted in a total of 50 CVE identifiers.[10]

Awards and recognition

[edit]

He has received the Pwnie Award four times: in 2012 in the "Best Privilege Escalation Bug" category, in 2013 in the "Most Innovative Research" category (together with Gynvael Coldwind), and in 2015 and 2020 in the "Best Client-Side Bug" category.[1][3] He was also nominated in other years, including in 2011 in the "Best Privilege Escalation Bug" category for a bug in the Windows CSRSS subsystem.[11] He was included in the Microsoft Security Response Center's annual list of the top 100 security researchers reporting to Microsoft, ranking eighth in 2018.[12] According to his website, he was on the list every year from 2015 to 2019 and ranked first in 2017.[1]

Publications

[edit]

He was a consultant and technical editor of Gynvael Coldwind's book Zrozumieć programowanie (2015)[13] and wrote its foreword.[14] Together with Coldwind he edited the book Praktyczna inżynieria wsteczna (2016), in which he also wrote the chapter "W pogoni za flagą – eksploitacja na systemach Windows i Linux".[15][16]

He has published articles in industry magazines, including Programista, where he wrote the series "Jak napisać własny debugger w systemie Windows" ("How to write your own debugger on Windows", 2014),[17] and the international HITB Magazine. His articles in the latter on the use of Windows kernel objects in vulnerability exploitation were cited, among others, by Tarjei Mandt in a paper presented at Black Hat DC 2011.[18] He publishes on the Project Zero blog and on his own blog, and has spoken at conferences including Black Hat, REcon and Infiltrate.[1]

Selected publications

[edit]
  • Mateusz Jurczyk; Gynvael Coldwind, eds. (2016). Praktyczna inżynieria wsteczna. Metody, techniki i narzędzia (in Polish). Warsaw: Wydawnictwo Naukowe PWN. ISBN 978-83-01-18951-8.
  • Jurczyk, Mateusz; Coldwind, Gynvael (2013), Identifying and Exploiting Windows Kernel Race Conditions via Memory Access Patterns, Google
  • Mateusz Jurczyk; Gynvael Coldwind (10 January 2014). "FFmpeg and a thousand fixes". Google Online Security Blog. Retrieved 29 September 2026.

References

[edit]
  1. 1 2 3 4 5 6 7 8 9 "About me". j00ru//vx tech blog. Retrieved 29 September 2026.
  2. 1 2 Grzegorz Marczak (13 April 2016). "Kim jest haker, kto może zostać dobrym hakerem i w jakim wieku?". AntyWeb (in Polish). Retrieved 25 September 2026.
  3. 1 2 3 Rutrell Yasin (6 August 2015). "'Will it Blend?' Earns Pwnie For Best Client Bug; OPM for Most Epic Fail". Dark Reading. Retrieved 29 September 2026.
  4. 1 2 Shaun Nichols (8 May 2020). "One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch". The Register. Retrieved 29 September 2026.
  5. 1 2 "Samsung patches a critical exploit its smartphones had since 2014". PhoneArena. Retrieved 4 October 2026.
  6. ↑ "CTFtime.org / Dragon Sector". CTFtime. Retrieved 25 September 2026.
  7. ↑ Mateusz Jurczyk; Gynvael Coldwind (10 January 2014). "FFmpeg and a thousand fixes". Google Online Security Blog. Retrieved 29 September 2026.
  8. ↑ "Identifying and Exploiting Windows Kernel Race Conditions via Memory Access Patterns". The Pwnie Awards. Retrieved 25 September 2026.
  9. ↑ Dan Raywood (2 August 2013). "Pwnie awards see gongs for Barnaby Jack, Edward Snowden and Dual Core". SC Magazine UK. Archived from the original on 22 November 2019. Retrieved 25 September 2026.
  10. 1 2 Mateusz Jurczyk (18 April 2024). "The Windows Registry Adventure #1: Introduction and research results". Project Zero. Retrieved 29 September 2026.
  11. ↑ Lucian Constantin (26 July 2011). "Pwnie Award Nominations Announced". Softpedia. Retrieved 29 September 2026.
  12. ↑ "Microsoft's Top 100 Security Researchers – Black Hat 2018 Edition". Microsoft Security Response Center. 8 August 2018. Retrieved 4 October 2026.
  13. ↑ Gynvael Coldwind: Zrozumieć programowanie. Warsaw: Wydawnictwo Naukowe PWN, 2015, imprint page. ISBN 978-83-01-18460-5. (in Polish)
  14. ↑ Gynvael Coldwind. "Książka napisana; spis treści, podcasty". gynvael.coldwind//vx.log (in Polish). Retrieved 3 October 2026.
  15. ↑ Mateusz Jurczyk, Gynvael Coldwind (eds.): Praktyczna inżynieria wsteczna. Metody, techniki i narzędzia. Warsaw: Wydawnictwo Naukowe PWN, 2016, title page and table of contents. ISBN 978-83-01-18951-8. (in Polish)
  16. ↑ "Praktyczna Inżynieria Wsteczna: Metody, techniki i narzędzia". j00ru//vx tech blog (in Polish). Retrieved 3 October 2026.
  17. ↑ "Jak napisać własny debugger w systemie Windows – część 2". Programista (in Polish). Retrieved 3 October 2026.
  18. ↑ Tarjei Mandt (2011). Kernel Pool Exploitation on Windows 7 (PDF). Black Hat DC. Retrieved 3 October 2026.
[edit]