
Abusing tclsh to Load (Remote) Shellcode on macOS
Yet another LOOBins

Yet another LOOBins

Yet another LOOBins

Bypass hardware assisted mitigation using Objective-C runtime.

Bypass hardware assisted mitigation using Objective-C runtime.

A simple access control issue makes a huge difference, leading to infoleak and use after free.

A simple access control issue makes a huge difference, leading to infoleak and use after free.

Remotely pwn iOS and pop up arbitrary app with 0 memory corruption.

Remotely pwn iOS and pop up arbitrary app with 0 memory corruption.

A rogue Wi-Fi hotspot can crash your phone.

A rogue Wi-Fi hotspot can crash your phone.

There is a turing-complete querying language embeded in Objective-C hidden in plain sight.

There is a turing-complete querying language embeded in Objective-C hidden in plain sight.

A funny bug chain turing inter-process XSS to native code execution for sandbox escape.

A funny bug chain turing inter-process XSS to native code execution for sandbox escape.

Copycat.

Copycat.

Triggering inter-process XSS for fun and profit.

Triggering inter-process XSS for fun and profit.

Useless bugs are just being given up too early.

Useless bugs are just being given up too early.