doing iOS&macOS security research

Joined August 2017
29 Photos and videos
21 Dec 2023
after months of hardwork đź‘€
117
118
1,005
229,953
26 Sep 2023
MOSEC BaijiuCon, an exciting experience! special thanks to @zh1x1an2
3
10
91
27,475
25 Sep 2023
I'm an iOS SEP app developer. đź‘€
4
27
239
48,318
My talk was accepted by BlackHat USA 2023. #BHUSA
5
13
151
26,446
proc_entitlement_is_bool_true("com.apple.private.security.container-manager") is changed to AppleMobileFileIntegrity::AMFIEntitlementGetBool in iOS 16.4. So the hack adding entitlements to the backend OSDictionary of OSEntitlements is not working.

4
11
57
26,531
29 Dec 2022
I hate debugging kernel. The only useful information is register values left in panic log.
1
8
62
23,097
me too🤣
5
2
53
15 Mar 2022
iOS 15.x demo. Run 3 cmds: ls, id, sw_vers. There is a lot of trouble in ios15. Still a long way from a real jailbreak. iPhone XS, iOS 15.0: using cve-2021-30883 (written months ago) iPhone 13 Pro, iOS 15.1: using cve-2021-30955 (thanks @realBrightiup ) I don't promise anything
67
197
1,141
pattern-f retweeted
27 Jan 2022
Had succeeded in using my kernel read/write primitive to achieve privilege elevation on macOS 12.1 prior to the release of macOS 12.2. The exploit code can work in many sandboxed context (apps, WebContent, etc.), but the vuln doesn't exist on iOS.
3
20
102
pattern-f retweeted
29 Dec 2021
unc0ver v8.0.0 is NOW OUT with iOS 14.6-14.8 support for A12-A13 iPhones. unc0ver.dev/

463
643
2,929
14 Dec 2021
An important thread. I recommend iOS hackers to read this. x.com/WangTielei/status/1470…

14 Dec 2021
iOS 15.2 fixed many bugs in IOMobileFrameBuffer (IOMBF), one of my favorite attack surfaces, and brought me a lot of good memories regarding IOMBF.
6
18
107
Write an iOS 14.6 (iPhoneXR, A12) jailbreak demo for CVE-2021-30883 (fixed in iOS 15.0.2, by @AmarSaar). Use a trick from oob-timestamp (by @_bazad). Run two commands: "id" and "ls /"
121
210
1,037
29 Oct 2021
These are the last two. Have stopped doing iOS vulnerability hunt for several months. So, no CVEs next time.
7
71
29 Oct 2021
I've been a little busy lately. Hope I could get back to the vulnhunt things soon.
2
40
29 Oct 2021
1 CVE, 3 people. Lucky, or unlucky?
3
1
61
29 Oct 2021
CVE-2021-30914 I used this one to complete my first iOS LPE exploit demo, on 2021-02-09, . Unfortunately, it is not easy to exploit it in iOS 14.2 and above.
10
24
144
14 Oct 2021
Write a jailbreak demo for CVE-2021-30883 (fixed in iOS 15.0.2, by @AmarSaar ) on an iPhone 11 iOS 14.0. Why iOS 14.0? I just want to verify if the vulnerability is exploitable. The code is based on the old ipc_kmsg hack. The exploit has better speed than cicuta_virosa.
55
208
967