Master Windows Internals - Kernel Programming, Debugging & Architecture
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This advanced talk explains how userland vulnerabilities in iOS 11 were chained to break the sandbox, bypass code signing, install a rogue application, and achieve persistence. It covers a double-free vulnerability in IOKit, reliable race-based exploitation, and a demonstrated attack strategy.
Syllabus
Intro
Agenda
Typical exploit chain (mobile Pwn20wn) 1/2
Why not a kernel bug to escape the sandbox?
iOS sandbox overview
Our strategy on sandbox bypass
General approach to exploit double free
Problem 1: fill in object B
Problem 2: stable race to fill
CF object fill into vm_allocate
The strategy doesn't work
Android Comparison
Pegasus APT
Initial Step: Setting up the required files
Final step, showing the app
Examining the roadblocks
iOS 12 sandbox hardening
Taught by
Recon Conference