Cybersecurity Research

Researchers Find New Way to Bypass Windows Kernel Security Protection

Project Zero · 4 Nov 2025
Key Takeaway Keep all business devices and servers set to install operating system updates automatically, as these often contain fixes for deep security issues like this one.

Google's Project Zero research team has published findings describing a method to defeat Kernel Address Space Layout Randomisation, commonly known as KASLR. This is a security feature used by operating systems to make it harder for attackers to exploit software flaws by randomly placing critical system code in memory, making it difficult to predict where to target an attack.

While the technical details are aimed at security researchers and software vendors rather than everyday users, the discovery is significant because KASLR is a widely relied-upon defence layer across many modern computers and servers. When protections like this are found to be bypassable, it can open the door for more advanced attacks if not addressed through software updates.

For small and medium businesses, this kind of research doesn't mean immediate danger, but it highlights the ongoing arms race between attackers and defenders at the operating system level. Vendors typically respond to such findings with patches, which is why staying current with updates remains one of the most effective, low-cost defences available to any business.

KASLR operating system security vulnerability research

Summarised by CISO AI from Project Zero. We link back to every original so you can read it yourself.