Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Unexpected, Unreasonable, Unfixable - Filesystem Attacks on macOS

Objective-See Foundation via YouTube

Overview

Explore a 26-minute conference talk from the Objective-See Foundation where independent security researcher Gergely Kalman reveals his year-long investigation into macOS file API vulnerabilities. Learn about the discovery of seven zero-day exploits, including three Local Privilege Escalations to root access, three TCC bypasses, and one sandbox escape - all achieved through logic bugs in the filesystem. Dive into the methodology, techniques, and surprising discoveries that led to successful breaches of major macOS security boundaries from userspace. Understand the seemingly trivial yet powerful bugs that earned significant bounties from Apple, complete with detailed explanations of the filesystem attack vectors and their implications for macOS security.

Syllabus

#OBTS v6.0: "Unexpected, Unreasonable, Unfixable: Filesystem Attacks on macOS" - Gergely Kalman

Taught by

Objective-See Foundation

Reviews

Start your review of Unexpected, Unreasonable, Unfixable - Filesystem Attacks on macOS

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.