We escaped Apple's Virtualization framework from guest to host on M5 Apple silicon, with PAC and MTE both enabled. The chain uses an intra-object corruption MTE doesn't catch by design, a data-property leak, and a paravirtualized media path that moves attacker state across the boundary. We'll show why that boundary forces two phases and how we dealt with PAC, then run it live on shipping macOS.
I built the rig that found these bugs. It's an AI harness modeled on how a real VR team splits the work, and pointing it at my own job was the experiment. It turned out to be good at finding bugs and grinding primitives, and bad at recognizing when it already had enough to win. The calls that closed the chain came from a human looking over its shoulder. The second half of the talk is that gap, reconstructed from the rig's own logs.
Josh Maine is the author of `ipsw`, the Apple firmware and dyld-shared-cache Swiss Army knife (if you do Apple work, it's probably already on your machine), and a security researcher at Calif. Twelve years of reverse engineering, the last eight-plus deep in Apple internals, mostly building the things other researchers stand on.