writeups.xyz writeups.xyz / Mickey Jin (@Patch1t)

Title Vulnerabilities Programs Authors
CVE-2023-42929: Why do we need the App Container Protection
macOS AUHelperService Full TCC Bypass
The Nightmare of Apple's OTA Update: Bypassing the Signature Verification and Pwning the Kernel
CVE-2022-32902: Patch One Issue and Introduce Two
CVE-2023-23525: Get Root via A Fake Installer
A Technical Analysis of CVE-2022-22583 and CVE-2022-32800
Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities
CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS
CVE-2022-26712: The POC for SIP-Bypass Is Even Tweetable
MacOS SUHelper Root Privilege Escalation Vulnerability: A Deep Dive Into CVE-2022-22639
CVE-2022-22616: Simple way to bypass GateKeeper, hidden for years