They simply have to show it against a beta version of MacOS, and frame it as unauthorized access, and maybe from locked mode if possible
First public macOS kernel memory corruption exploit on Apple M5
11–20 of 140 posts
Re: First public macOS kernel memory corruption exploit on Apple M5
#12Re: First public macOS kernel memory corruption exploit on Apple M5
#13unfortunately a little light on the details. I'm very curious how the bug survived through MTE
GPU memory/shaders/etc. isn't protected by MTE or PAC. They said "data-only", so I guess GPU commands could fit into this description.
Re: First public macOS kernel memory corruption exploit on Apple M5
#14from what they demonstrated, this seems to only be a $100,000 exploit in Apple's bug bounty platform, but if they package it right, it could be a $1.5 million exploit They simply have to show it against a beta version of MacOS, and frame it as unauthorized access, and maybe from locked mode if possible
Re: First public macOS kernel memory corruption exploit on Apple M5
#15I bought the M5 specifically cause of MIE. Now I feel dumb.
Re: First public macOS kernel memory corruption exploit on Apple M5
#16[flagged]
Re: First public macOS kernel memory corruption exploit on Apple M5
#17Re: First public macOS kernel memory corruption exploit on Apple M5
#18Earlier quoted context omitted.
Cisco put up a totally bogus 10.0 CVE just for this reason, too
? can you expand?
Re: First public macOS kernel memory corruption exploit on Apple M5
#19from what they demonstrated, this seems to only be a $100,000 exploit in Apple's bug bounty platform, but if they package it right, it could be a $1.5 million exploit They simply have to show it against a beta version of MacOS, and frame it as unauthorized access, and maybe from locked mode if possible
This is an lpe I believe what you’re describing is a zero click rce.