#NullconBerlin2025 | A Deep Dive into A Vulnerability Apple Deems Unexploitable by Mickey Jin

33:28 · 04 Sep 2025 – 05 Sep 2025 · YouTube

About this talk

This talk covers a critical race condition vulnerability in Apple’s core file-copy APIs, which are essential for file management across devices like macOS, iOS, and watchOS. The speaker, Mickey Jin, discusses how Apple was aware of the security risk but underestimated its exploitability, leaving devices open to potential attacks. He explains the development of a reliable exploit program that takes advantage of this vulnerability to access user secrets. Although Apple has released a patch addressing this issue, the speaker reveals that it can be easily bypassed, and he outlines what to expect from Apple's forthcoming solutions.

From event

Nullcon Berlin 2025

04 Sep 2025 – 05 Sep 2025

All event videos
Back to Watch