In this talk I will present 6 findings from my backlog, totalling $135k worth of bounties. All of the bugs are file-operation-based logic vulnreabilities, a few of them are trivial to exploit and a few others are fairly difficult race conditions. The impact is 1x root LPE, 4x TCC bypass (FDA), 1x SIP bypass (which is also a TCC bypass).
I will demonstrate how trivial some of these bugs are to find and exploit, and I will talk about Apple's recent decision to reduce the TCC bypass bounties by ~84%, and what this means to security researchers in the program.
I will also discuss practical exploitation of race conditions,
particularly races inside the kernel's path-resolution to bypass Apple's new
O_RESOLVE_BENEATH protection. I will also discuss hijacking the
macOS dynamic loader using chroot, which - I believe - is something
that has not been done publicly before.
Gergely is an independent security researcher, spending most of his time on Apple's Bug Bounty program. As an ex-sysadmin and programmer he is adept at Linux, Python and C and he specializes in logic vulnerabilities, often involving filesystems or file APIs. He publishes his findings at https://gergelykalman.com