BEGIN:VCALENDAR
PRODID:-//Google Inc//Google Calendar 70.9054//EN
VERSION:2.0
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:44CON 2026
X-WR-TIMEZONE:Europe/London
BEGIN:VEVENT
DTSTART:20260917T101000Z
DTEND:20260917T110000Z
DTSTAMP:20260624T151157Z
UID:3b08mfr9f51nh050ko7ophevd7@google.com
CREATED:20260624T131934Z
DESCRIPTION:Forget prompt injection. While the industry obsesses over ma
 nipulating model inputs to bypass guardrails\, it is overlooking a far more
  dangerous threat requiring no user interaction beyond opening the applicat
 ion embedded beneath the AI itself: the underlying platform architecture.\nTo deliver on the promise of full autonomy\, AI-powered coding environ
 ments wire Large Language Models directly into the developer workflow—handi
 ng them local filesystem access\, shell execution\, and cloud credentials. 
 Developers accept this tradeoff for the massive productivity gains\, but th
 e security cost is severe.\nIn these environments\, privileged OS acce
 ss is not a misconfiguration but a product requirement. For a chat interfac
 e to truly become an autonomous “agent\,” it must be equipped with tools. E
 quipping the AI with these tools creates a structural conflict with traditi
 onal application isolation\, like Electron’s security model. To make the AI
  function\, developers are forced to break the sandbox and expose highly pe
 rmissive IPC (Inter-Process Communication) bridges between the web renderer
  and the local operating system.\nThis presentation provides a technic
 al deep dive into how chained IDOR vulnerabilities can be escalated into ze
 ro-click RCE via persistent LLM conversation injection and unsafe Electron 
 IPC designs. To prove the real-world impact\, we will debut novel research 
 into Orchids\, a leading local\, Electron-based AI coding IDE with over a m
 illion users\, reported to be used by teams at firms including Google\, Ama
 zon\, and Uber.\nBy weaponizing the IDE’s automated context ingestion\
 , we turn the platform’s own features into a silent backdoor\, achieving fu
 ll remote system takeover with no user interaction beyond opening the appli
 cation.\nAttendees will leave this session with a practical understand
 ing of this emerging attack surface\, a live demonstration of the zero-clic
 k exploit chain\, and actionable defensive design patterns for safely archi
 tecting the next generation of AI-enabled desktop applications.
LAST-MODIFIED:20260624T131935Z
LOCATION:Track 2
SEQUENCE:0
STATUS:CONFIRMED
SUMMARY:VibeShell: How Trusting Your AI IDE Costs You Your Machine – Etizaz
  Mohsin
TRANSP:OPAQUE
END:VEVENT
END:VCALENDAR