Whoah... $250000
(CVE-2025-4609, similar to CVE-2025-2783/412578726)[412578726][Mojo][IpczDriver]ipcz bug -> renderer duplicate browser process handle -> escape sbx is now open with PoC & exploit(success rate is nearly 70%-80%)
https://t.co/KiQ6gHaHVj
https://t.co/5TXy8yIC0g
Just finished a new blog sharing an interesting example demonstrating the power of cross-operating system vulnerability variant analysis! Check it out here: https://t.co/AdCDUhVtGz
Hope you like it.
Thrilled to share our latest deep dive into Windows Kernel Streaming!
Just presented this research at @offensive_con.
Check it out: https://t.co/DRxHWf5pTJ
@theevilbit Perhaps it's due to different reviewers. In fact, my single category TCC bypass in 2023 still received 15.5k. Only issues that involve restrictions (root permission) or require user interaction would be awarded 5k.
@theevilbit I asked Apple half a month ago if there was any error in this CVE description. Apple didn't reply or correct it (BTW, the inspiration for this issue is from your paper in BlackHat).
@theevilbit Yes, I'm OK with this. It's just that one month's reply is too long. What's worse is that this issue has not been fixed. Once again, Apple confused my report with others.
New writeup:
CVE-2025-24104 – Apple’s bug allowed arbitrary file reads outside the sandbox.
While iOS 18.3 added a mitigation, it doesn’t fully fix the issue. I even bypassed it since my recommended fix wasn’t followed.
Read more 👉 https://t.co/NmnHKrra8k
#AppleSecurity #CVE2025 #InfoSec
Two new posts from @tiraniddo today:
https://t.co/StB2knG8FO on reviving a memory trapping primitive from his 2021 post.
https://t.co/sbKodaJMe9 where he shares a bug class and demonstrates how you can get a COM object trapped in a more privileged process.
Happy Reading! 📚
🍎🪳Second part of the diskarbitrationd - storagekitd vulnerability blog series is out on @KandjiOfficial 's blog.
These vulnerabilities were presented at @BlackHatEvents#BHEU2024 and @POC_Crew#POC2024 conferences.
https://t.co/wjT5V6RjwZ
As promised, I just dropped a dozen new sandbox escape vulnerabilities at #POC2024
If you missed the talk, here is the blog post:
https://t.co/zTcENNrZun
Slides:
https://t.co/sWztf0ygM4
Enjoy and find your own bugs 😎