Archives

2024-11-24
badmalloc (CVE-2023-32428) - a macOS LPE
2024-10-02
Tool release: fs_usage_ng
2024-09-12
The forgotten art of filesystem magic - Alligatorcon 2024 slides
2024-08-20
The missing guide to the security of filesystems and file APIs (v1)
2024-04-12
Why you shouldn't use a commercial VPN: Amateur hour with Windscribe
2023-12-18
Hacking ISP CPE equipment: FiberHome
2023-12-18
You can watch my OBTSv6 talk on youtube
2023-11-15
sqlol (CVE-2023-32422) - a macOS TCC bypass
2023-11-14
lateralus (CVE-2023-32407) - a macOS TCC bypass
2023-10-30
batsignal (no CVE) - a macOS LPE
2023-10-15
Unexpected, Unreasonable, Unfixable - My slides from OBTS v6
2023-09-27
librarian (CVE-2023-38571) - a macOS TCC bypass in Music and TV
2023-09-26
unnamed sandbox escape (CVE-2023-32364) - a macOS sandbox escape by mounting