November 5, 2024

Hacker 08Tc3wBB to Present 'Kernel Exploitation On Apple's M1 Chip' at OBTS

Posted September 8, 2021 at 1:45am by iClarified · 7361 views
Hacker 08Tc3wBB will present an Apple M1 kernel exploitation at the upcoming Objective by the Sea macOS security conference.

The bug bounty hunter and security researcher at ZecOps announced the exploit talk on Twitter...

---
As the Mac product line gradually enters the M1 chip era, the macOS security of the arm64e architecture is beginning to approach iOS. The mitigations that only existed on iOS in the past are now also applicable to macOS. As well as... the vulnerabilities that only affected iOS in the past are now also brought into macOS. Lol.

AppleAVE2 (AVEVideoEncoder) is a graphics IOKit driver that runs in kernel space and exists only on iOS and M1 chip-based Macs. The complexity of the drive itself and the extensive use of user-kernel memory mapping make it a desirable target for kernel exploitation. I used it to develop kernel exploits for iOS 12 and iOS 13 Jailbreak. CVE-2019-8795, CVE-2020-9907, CVE-2020-9907b.

This talk will explain in detail how Apple "fixed" the AppleAVE2 driver and how we can exploit AppleAVE2 once again to achieve kernel r/w on M1 Macbook, at last I'll share some of my thoughts on post-exploitation.
---

More details on the OBTS conference dates and presentations can be found on the link below. Please download the iClarified app or follow iClarified on Twitter, Facebook, YouTube, and RSS for updates.

Read More