Posts
- December 5, 2025 macOS LPE via the .localized directory
- December 12, 2024 The diskarbitrationd and storagekitd Audit Story Part 2
- November 8, 2024 The diskarbitrationd and storagekitd Audit Story Part 1
- July 19, 2024 Dock Tile Plugins Could Be Used to Escalate Privileges
- May 24, 2024 CVE-2023-40424 - How Malware Can Bypass Transparency Consent and Control
- March 15, 2024 How Apple Mitigates Vulnerabilities in Installer Scripts
- October 9, 2023 Launch and Environment Constraints Deep Dive
- September 28, 2023 macOS Service Management - The SMAppService API - Quick Notes
- February 13, 2023 CVE-2022-22655 - TCC - Location Services Bypass
- November 14, 2022 CVE-2022-32929 - Bypass iOS backup's TCC protection
- October 24, 2022 Prologue - The Lord of The Rules
- August 29, 2022 CVE-2017-2533 - The details behind
- June 14, 2022 AMFI Launch Constraints - First Quick Look
- October 29, 2021 CVE-2021-30808 - CVE-2021-1784 strikes back - TCC bypass via mounting
- September 27, 2021 Getting started in macOS security
- June 29, 2021 GateKeeper - Not a Bypass (Again)
- June 10, 2021 macOS Monterey Shortcuts - First look
- May 26, 2021 NOCVE - TeamViewer Local Privilege Escalation Vulnerability
- April 23, 2021 Experiences with Apple Security Bounty
- April 20, 2021 CVE-2020-9900 & CVE-2021-1786 - Abusing macOS Crash Reporter