#NullconBerlin2025 | A Deep Dive into A Vulnerability Apple Deems Unexploitable by Mickey Jin
About this talk
This talk covers a critical race condition vulnerability in Apple’s core file-copy APIs, which are essential for file management across devices like macOS, iOS, and watchOS. The speaker, Mickey Jin, discusses how Apple was aware of the security risk but underestimated its exploitability, leaving devices open to potential attacks. He explains the development of a reliable exploit program that takes advantage of this vulnerability to access user secrets. Although Apple has released a patch addressing this issue, the speaker reveals that it can be easily bypassed, and he outlines what to expect from Apple's forthcoming solutions.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
29:22
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
37:23
#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
35:03