"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her
"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her
Posts
"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her
"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her
"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her
"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her
"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her
Memory Integrity Enforcement is the culmination of a truly incredible amount of work :)
While there's so much to love, one of my favorite pieces was getting to bring kalloc_type-style isolation to out-of-bounds accesses on both the architectural and speculative path. This lets us both mitigate a variety of Spectre v1 style attacks and break the reliable exploitation of some of the most powerful first-order memory corruption primitives (arb offset OOB R/W).
https://security.apple.com/blog/memory-integrity-enforcement/
"if i had a nickel for every time i accidentally found a zero click RCE, i'd have two nickels, which isn't a lot but it's weird that it happened twice" she/her