To celebrate iOS 27’s release, why not release a sandbox escape?
Announcing airlift: a PoC abusing a media sync path for out-of-scope access across much of /var/mobile via macOS↔iOS pairing.
No MobileGestalt edits yet; looking into it.
https://t.co/NXpVzwvgfH
@ncxcq Bro you were really fighting me over “AI slop”and saying my stuff was AI generated while yours was “written with hands”… then you drop a repo that opens with “Claude code was used for documenting markdown.” Make it make sense.
@AboGhzayel Yeah it won't work because the KASLR slide, stale_id, IOGPUDevice resource table offset, IOGPUSysMemory field offsets, getattrlist packed size, OOB slot offset, vfs_attr_pack_internal VA etc. are all hardcoded for ip 12. You need to analyze the kernelcache for your device model.
@AboGhzayel The reason it won't work standalone is because it needs the https://t.co/J21w7aeqji.private.AppleKeyStore entitlement which a sideloaded app doesn't have or the fishhook to intercept SecKeyCreateRandomKey which is blocked on 26 because __DATA_CONST is read-only.
@AboGhzayel You modified the code for your chip right? Cause the code on github is for A14. Also you might need different entitlements depending on setup.