CVE-2025-43530: Exploiting a private API for VoiceOver
Happy New Year in advance!
Exploring the world with my sword of debugger :)
Happy New Year in advance!
This is a blog post for my presentation at the conference Nullcon Berlin 2025. The slides are uploaded here.
Today, I am disclosing a 0-day vulnerability that bypasses the patch for CVE-2024-34331. I have identified two distinct methods to circumvent the fix. Both bypasses were reported separately to the Zero Day Initiative (ZDI) and the affected vendor Parallels. Unfortunately, their responses have been deeply unsatisfactory.
This is a blog post for my presentation at the conference OBTS v7.0. The slides are uploaded here.
Happy New Year!
This is a blog post for my presentation at the conference POC2024. The slides are uploaded here.
Starting with macOS Sonoma 14.0, Apple has introduced a new TCC category kTCCServiceSystemPolicyAppData to protect the App Container Data. This is designed to address one of my reports (aka CVE-2023-42929):
About two weeks ago, Apple published the CVE-2023-42942 in the security advisory. It was a race condition issue existed in the system service xpcroleaccountd, and it could be exploited for root privilege escalation. Today, I am going to share the details.
Last year, I discovered a full user TCC bypass issue in the macOS Sonoma beta version. There was a CVE number assigned at the beginning, but removed by Apple in the release of macOS 14.0. Instead, I got the credit in their Additional Recognitions.
This blog post is written for my talk at OBTS v6.0.