RSSAmplifier

Blog

Siguza's Blog

iOS security, vulnerabilities, exploits, hardware mitigations, reverse engineering, that sort of stuff.

blog.siguza.netRSS feed ↗12 posts

Latest posts

tachy0n

iOS kernel exploit for 13.0-13.5 that was dropped as an 0day in unc0ver v5.0.

"Psychic paper"

How to escape the iOS sandbox before your code even runs. Patched in iOS 13.5 beta 3.

cuck00

An all-too-simple XNU kernel info leak that was hiding in plain sight for two decades. Patched in iOS 13.3.1 beta 2.

PAN

A design flaw in the ARMv8 specification.

APRR

Teardown of a hardware memory permission mitigation introduced in Apple's A10/A11 chips.

The Evolution of iOS Mitigations

TyphoonCon 2019 Slides

IOKit resymbolication

How to find a couple dozen thousand C++ symbols for an iOS kernel with minimal effort.

KTRR

Teardown of a hardware kernel integrity mitigation introduced in Apple's A10 chip.

The HIDeous parts of IOKit

Zer0Con 2018 Slides

IOHIDeous

A macOS kernel exploit I dropped as an 0day just for the lulz. Patched in macOS High Sierra 10.13.3.

v0rtex

The kernel exploit that powers a bunch of iOS 10 jailbreaks.

cl0ver

"tfp0 powered by Pegasus": the first binary exploit I ever wrote - gets kernel r/w on iOS 9.