
Rootpipe Reborn (Part I): TimeMachine Command Injection
Applying web security tricks to macOS LPE bugs.

Applying web security tricks to macOS LPE bugs.

Applying web security tricks to macOS LPE bugs.

TOCTOU bug in CoreFoundation and state change of sandbox lockdown on macOS Safari, leading to easy sandbox escape.

TOCTOU bug in CoreFoundation and state change of sandbox lockdown on macOS Safari, leading to easy sandbox escape.

The private API design of XPC could make it hard for 3rd-party developers to write security code.

The private API design of XPC could make it hard for 3rd-party developers to write security code.

Code signature bypass and insecure sideloading result in privilege escalation in Microsoft Office 2016 for Mac

Code signature bypass and insecure sideloading result in privilege escalation in Microsoft Office 2016 for Mac

Get some real life 0day by playing CTF challenges.

Get some real life 0day by playing CTF challenges.

Attacking the operating system by using its own security mechanism.

Attacking the operating system by using its own security mechanism.