Discovering iOS 0-Days with Muse Spark
With Muse Spark's release, we wanted to see how far its capabilities could be pushed against a real, high-value target. We started with ImageIO on iOS - a framework whose bugs land squarely on Meta's Family of Apps given how much media flows through our platforms.
The first problem wasn't finding bugs, it was teaching the model what an ImageIO vulnerability actually looks like: the shape of the bug class, the 0-click parsing paths that matter, and the primitives that make one interesting. From there, we taught it to generalize - to take a known issue and reason about where its variants live.
This talk walks through the agentic pipeline we built around IDA, BinDiff, and LLDB: how the model drives static diffing, forms hypotheses, and validates them dynamically.
Luke McLaren (@datalocaltmp) is a security engineer at Meta, working on mobile security, messaging app attack surface, and vulnerability research. His current work focuses on driving vulnerability research into high-value third-party components with Muse Spark.
Most of his public work has focused on messaging apps and remote access vectors. He presented ""Call, Crash, Repeat: WhatsApp Hacking"" at REcon 2025, covering remote crashes reachable through WhatsApp's call signaling path, and ""Messenger Bug Hunting"" at ekoparty 2024. At DEFCON 32 he presented ""Pwning through the Metaverse: Quest Headset Vulnerability Research"" on fuzzing the Quest's Android native layer into a remotely triggerable heap overflow in avatar deserialization.
Recent hobby projects have included porting the Darksword kernel exploit to the Apple Watch.