XNU heap exploitation: From kernel bug to kernel control | Tihmstar | NULLCON Goa 2020
About this talk
This talk explores the exploitation of two kernel vulnerabilities, CVE-2018-4344 and CVE-2019-6225, by presenting three kernel exploits: treadm1ll, v1ntex, and v3ntex. It begins with a brief introduction to the XNU internals, specifically focusing on Mach ports and heap allocators like zalloc and kalloc. The speaker demonstrates the progression from proof of concept to fully developed kernel exploit, emphasizing the exploitation techniques and the manipulation of heap memory. Additionally, the talk considers changes between iOS versions 11 and 12 that affect the exploitation process, highlighting that even minor modifications to the exploit chain can lead to significant impacts.
More from this event
See all 39 talks →
ML for security and security for ML | Training Tidbits | Nikhil Joshi | NULLCON Goa | March 2020
0:30
Practical IoT Hacking | Training Tidbits | Aseem Jakhar | NULLCON Goa | March 2020
0:54
Hacking iOS Applications, Like A Pro | Training Tidbits | Abhinav Mishra | NULLCON Goa | March 2020
1:14
Windows Kernel Exploitation - Foundation & Advanced | Training Tidbits | Ashfaq Ansari #NULLCON2020
0:36