RSSAmplifier

Blog

Mickey’s Blogs

Exploring the world with my sword of debugger :)

jhftss.github.ioRSS feed ↗10 posts

Latest posts

CVE-2025-43530: Exploiting a private API for VoiceOver

Happy New Year in advance!

Exploiting the Impossible: A Deep Dive into A Vulnerability Apple Deems Unexploitable

This is a blog post for my presentation at the conference Nullcon Berlin 2025. The slides are uploaded here.

Dropping a 0 day: Parallels Desktop Repack Root Privilege Escalation

Today, I am disclosing a 0-day vulnerability that bypasses the patch for CVE-2024-34331. I have identified two distinct methods to circumvent the fix. Both bypasses were reported separately to the Zero Day Initiative (ZDI) and the affected vendor Parallels. Unfortunately, their responses have been deeply unsatisfactory.

Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times

This is a blog post for my presentation at the conference OBTS v7.0. The slides are uploaded here.

CVE-2024-54527: MediaLibraryService Full TCC Bypass, Dive Deep into AMFI

Happy New Year!

A New Era of macOS Sandbox Escapes: Diving into an Overlooked Attack Surface and Uncovering 10+ New Vulnerabilities

This is a blog post for my presentation at the conference POC2024. The slides are uploaded here.

CVE-2023-42929: Why do we need the App Container Protection

Starting with macOS Sonoma 14.0, Apple has introduced a new TCC category kTCCServiceSystemPolicyAppData to protect the App Container Data. This is designed to address one of my reports (aka CVE-2023-42929):

CVE-2023-42942: xpcroleaccountd Root Privilege Escalation

About two weeks ago, Apple published the CVE-2023-42942 in the security advisory. It was a race condition issue existed in the system service xpcroleaccountd, and it could be exploited for root privilege escalation. Today, I am going to share the details.

macOS AUHelperService Full TCC Bypass

Last year, I discovered a full user TCC bypass issue in the macOS Sonoma beta version. There was a CVE number assigned at the beginning, but removed by Apple in the release of macOS 14.0. Instead, I got the credit in their Additional Recognitions.

The Nightmare of Apple’s OTA Update: Bypassing the Signature Verification and Pwning the Kernel

This blog post is written for my talk at OBTS v6.0.