It's been just over a year since CVE-2024-54529 was patched. To celebrate, I'm open-sourcing my full PoC exploit for this CoreAudio type confusion vulnerability 🔊
The code is right here! Enjoy: https://t.co/GRvILp6C84
I’m really excited for us to shed light on some really cool work we’ve been doing to harden the XNU allocator! This has been a huge effort by so many people, and I’m very proud of the direction: https://t.co/aW4LXuKbWV
Excited to announce my new book series: "The Art Of Mac Malware" https://t.co/jgTOCd34DU 📚
🆓 100% free online
📝 Peer-reviewed & open for comments
When published, proceeds will support our #OBTS conference & charity efforts 😍 #SharingIsCaring
The latest guest blog from the Trend Micro Research Team details CVE-2019-0230: remote code execution in Apache Struts framework due to insufficient input validation leading to a forced double Object Graph Navigation Library (OGNL) evaluation. https://t.co/Lk1GANcYpg
The core of Apple is PPL: Attacking the XNU kernel's kernel. https://t.co/7f15UG2s9J
How to use an out-of-bounds read in PPL (Apple's kernel-within-the-kernel) to get a stale TLB entry for a page, allowing you to bypass PPL and map arbitrary physical addresses accessible at EL0.
If you need to debug a Linux kernel Hyper-V guest check out https://t.co/S2OP8FNl3v.
Allows you to kernel debug the guest from WSL on the host which is neat.
New features added to our project's repository!
* iOS on QEMU KVM support
* ASLR disabled for user mode
* TFP0 for user apps
* CoreTrust patched - no need for static trust cache
Check it out and feel free to contribute!
https://t.co/uClu4PGVva