https://en.wikipedia.org/wiki/Npm_left-pad_incident
Thankfully, we've completely solved software supply chains in the years since.
At long last, we have stolen the macOS from classic kernel extension Dont Steal Mac OS.kext
Kaspersky researchers just found and presented a Snapdragon 410/210/617 bootrom exploit - CVE-2026-25262 in this month’s Qualcomm security bulletin.
It’s well known that every forensics tool supported exploiting those SoCs from the bootrom, but for 9 years, nobody knew how they were doing it.
This is some amazing research that finally solves the mystery..
I’m sure the BananaHackers community of Snapdragon 210 flip phone modders will find a use for this.
Still reading through gracecondition’s DirtySlide writeup (https://gracecondition.github.io/posts/dirtyslide/).
The writeup says it’s only usable in a macOS virtual machine - not a physical macOS/iOS device. Has anyone looked further into this?
The writeup gives two reasons:
Triggering 536 in the vulnerable context needs an application sandbox bypass.
iOS does support residing shared caches:
_POSIX_SPAWN_RESLIDE.And the shared_region_map_and_slide_2_np syscall exists
iOS should allow the syscall, at any rate:
https://github.com/Lessica/iOS-Sandbox-Profiles/blob/9bf1164cee918fcbf09bb918ef277d2dccfe8078/profiles/23C55__iPhone12%2C1/builtin_collection/container/container.sb#L9789
(unless you’re in lockdown mode in WebKit?)
https://github.com/WebKit/WebKit/blob/30dcf5d1c9402dea5a26158e103f7e4333a7eac2/Source/WebKit/WebProcess/com.apple.WebProcess.sb.in#L1241
It also needs an SPTM (Secure Page Table Monitor) bypass
Do you have to spray page tables or can you spray something else that also lands in the physmap?
I mean, I doubt anyone will actually look into this, since a kernel r/w isn’t enough for a jailbreak. It can only do kfd-style mods, and we already have those on iOS 26.0 via Darksword.
32 GB of RAM?
We're going to need a miracle.
██ENG███
█OOMSDAY
@AlesandroOrtiz@infosec.exchange Yes. (Every time I run netstat -a -n on my computer, I see this port, and every time I go on the internet and search for it.)
@65GHz@toots.nu curses, I missed the "A file descriptor of -1 is used to indicate that the data to be put in the shared region for this mapping comes directly from the processes address space." branch in shared_region_map_and_slide_setup.
Make the neighbour a page table Could you put something else there?
Huh, macOS 15.7.7 removes MACH_VOUCHER_ATTR_KEY_TEST from the kernel. https://github.com/apple-oss-distributions/xnu/blob/5c306bec31e314fa4d8bbdafb2f6f5a6b7e7b291/osfmk/ipc/ipc_voucher.c#L2761 According to the comments, iOS already removed the whole voucher subsystem, anyways, so it’s not interesting - but I wonder why they had something named _TEST compiled into a production kernel…