Nullcon Berlin 2024 | Fuzzing At Mach Speed: Uncovering IPC Vulnerabilities On MacOS By Dillon
About this talk
This talk explores the security of macOS Inter-Process Communication (IPC), particularly focusing on Mach message handlers and their role in executing privileged remote procedure call-like functions. The speaker examines the potential for sandbox escapes and privilege escalations, detailing the internals of macOS, the processing of Mach messages, and their data formats. A key component of the research is the development of a custom fuzzing harness designed to target IPC function handlers, aiming to uncover memory corruption vulnerabilities. The presentation discusses the results of the fuzzing process, including several crashes that may lead to remote code execution, and concludes by open-sourcing a Mach message corpus generation script and fuzzing harness to advance cybersecurity research.
More from this event
See all 15 talks →
Nullcon Berlin 2024 | Breaking RSA Authentication & Bitstream Recovery From Zynq-7000 SoC-Arpan Jati
42:15
Nullcon Berlin 2024 | How Things Are Going For APT41 In 2024 - Georgy Kucherin
32:28
Nullcon Berlin 2024 | Revela: Unlock The Secrets Of Move Smart Contracts- Nguyen Anh Quynh & Van Hoa
43:31
Nullcon Berlin 2024 | Fault Injection And The Supply Chain - Nolen Johnson and Jan Altensen
37:18