#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
About this talk
This talk by Koh M. Nakagawa explores a critical vulnerability in macOS that undermines process isolation, a key component of its security architecture upheld by System Integrity Protection (SIP). The speaker reveals how this vulnerability allows malicious actors to read memory from any process, even with SIP active, thereby compromising sensitive information stored in the Keychain and bypassing TCC protections. Additionally, the exploit facilitates the decryption of FairPlay-encrypted iOS apps on macOS, enhancing opportunities for iOS application penetration testing. Through a live demonstration, attendees will understand the significance of maintaining robust process isolation and methods for detecting such vulnerabilities, with all proof-of-concept code made available on GitHub.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
37:23
#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
35:03
#NullconBerlin2025 | Finding Bugs in V8: A Formal Verification Approach by Simon Gerst
36:58