~ Personal news ~
I left TechCrunch. I will now focus on finishing my book about Hacking Team and the history of government spyware.
After that, and in the meantime, I will be freelancing.
Contact me: [email protected] or Signal @ LorenzoFB.1337 (+1 917 257 1382)
New in iOS 27.0:
• Updated Liquid Glass design with customization slider, and refined icons
• Chatbot style Siri AI and Siri app*
• More Apple Intelligence features**:
- Extend and Reframe in Photos
- Create Shortcuts bye describing them
- More Image Playground options
• Various performance improvements including 80% faster AirDrop transfers
• New and expanded child safety features
and more: https://t.co/UnmfzkCPlV
* Not available in the EU and China. In the EU it is available on macOS 27.
** Not available in China.
#iOS27
The 40-year-old iOS kernel bug I discovered on the DEFCON 34 main stage.
My demo crashed on stage, and after investigating I traced it to a mistyped ++ that goes back to 1985.
Can you spot the bug?
Full post:
https://t.co/e3vuomAJ8r
I got the latest iOS and macOS 27 booting in Qemu (with SPTM!)
- Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac supported
- Debug, patch, or modify everything: kernel, SPTM, TXM, launchd, dyld, user programs all modifiable/ GDB-able
- Boots directly to root shell in seconds
- Run your own programs as root in iOS/ macOS, no jailbreak / kernel patches required
- SPTM, TXM, MTE/MIE, genter/ gexit, GXF/SPRR/GL0-2, AMCC, AIC v1-3, Apple timer, many sysregs
- Automated setup; get running in just a few minutes
- Runs anywhere qemu runs... no ARM CPU required 😉
Try it here: https://t.co/PEydRXL25G
Apparently, writeups are becoming a regular thing here :)
This time, added details and PoC for a regression in AppleM2ScalerCSCDriver that causes attacker supplied IOSurface KVA leak. Fixed in *OS 26.6:
https://t.co/vt8NobXpcS
New write-up with @GenericCoding on pois0nSword, our iOS 26.1 port of DarkSword: bypassing PAC to reach arbitrary native calls from a WebKit renderer R/W, by making dyld's own loader do the write.
https://t.co/pVJm0wtowR
#WebKit#JavaScriptCore#iOS#exploitdev
People say CVE-2026-43724 is unreachable on iOS because of _POSIX_SPAWN_RESLIDE. Think again. Test done on MIE-enabled device.
(Disclaimer: I can’t promise if anything useful may come out of this, need more research; thanks @Little_34306 for porting to iOS)
This blog reverse-engineers how Apple's MIE works inside the iOS 26 kernel - hardware memory tagging that mitigates buffer overflows, UaF, and type confusion with near-zero overhead: https://t.co/16Ih0F6qqF
Three pillars: type-aware allocators, Enhanced MTE with synchronous faults, and SPTM hypervisor protection that guards tag storage even with a compromised kernel.
Follow @8kSec for more iOS kernel research.