tl;dr
- UAF in chess game, overwrite
__malloc_hooktoone_gadget
tl;dr
__malloc_hook to one_gadgettl;dr
; secure; samesite=none to cookie. Now, <script src="https://jason.2021.chall.actf.co/flags?callback=load"></script> would retrieve the flag.