Unearthing Vulnerabilities in the Apple Ecosystem - The Art of KidFuzzerV2.0
OffensiveCon via YouTube
Overview
Dive into the intricacies of Apple's kernel space vulnerabilities in this 29-minute conference talk from OffensiveCon23. Explore the structure, attack surfaces, and mitigations of Apple's kernel space, and gain insights into vulnerability research techniques. Learn about entitlements collection, backward fuzzing, and the discovery of a 20-year-old attack surface through code diffing. Uncover high-level root causes behind bugs and delve into co-processor vulnerabilities. Gain valuable knowledge on unearthing vulnerabilities in the Apple ecosystem using KidFuzzerV2.0, with a comprehensive overview of the topic and relevant references provided.
Syllabus
Intro
Apple Kernel Space Structure
Apple Kernel Space Attack Surfaces
Apple Kernel Space Mitigations
Apple Kernel Space VR thoughts
Entitlements collection
Backward Fuzzing
A 20 year old attack surface by code diff
Extract high level root cause behind the bug
Other tales about Co-processor bugs
Summary
References
Taught by
OffensiveCon