#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh

29:22 · 04 Sep 2025 – 05 Sep 2025 · YouTube

About this talk

This talk by Koh M. Nakagawa explores a critical vulnerability in macOS that undermines process isolation, a key component of its security architecture upheld by System Integrity Protection (SIP). The speaker reveals how this vulnerability allows malicious actors to read memory from any process, even with SIP active, thereby compromising sensitive information stored in the Keychain and bypassing TCC protections. Additionally, the exploit facilitates the decryption of FairPlay-encrypted iOS apps on macOS, enhancing opportunities for iOS application penetration testing. Through a live demonstration, attendees will understand the significance of maintaining robust process isolation and methods for detecting such vulnerabilities, with all proof-of-concept code made available on GitHub.

From event

Nullcon Berlin 2025

04 Sep 2025 – 05 Sep 2025

All event videos
Back to Watch