Nullcon Berlin 2024 | Fuzzing At Mach Speed: Uncovering IPC Vulnerabilities On MacOS By Dillon

52:57 · 14 Mar 2024 – 15 Mar 2024 · YouTube

About this talk

This talk explores the security of macOS Inter-Process Communication (IPC), particularly focusing on Mach message handlers and their role in executing privileged remote procedure call-like functions. The speaker examines the potential for sandbox escapes and privilege escalations, detailing the internals of macOS, the processing of Mach messages, and their data formats. A key component of the research is the development of a custom fuzzing harness designed to target IPC function handlers, aiming to uncover memory corruption vulnerabilities. The presentation discusses the results of the fuzzing process, including several crashes that may lead to remote code execution, and concludes by open-sourcing a Mach message corpus generation script and fuzzing harness to advance cybersecurity research.

From event

Nullcon Berlin 2024

14 Mar 2024 – 15 Mar 2024

All event videos
Back to Watch