tl;dr
- UAF in chess game, overwrite
__malloc_hook
toone_gadget
tl;dr
__malloc_hook
to one_gadget
tl;dr
; secure; samesite=none
to cookie. Now, <script src="https://jason.2021.chall.actf.co/flags?callback=load"></script>
would retrieve the flag.