macOS LaunchDaemon iOS 17.2 – Privilege Escalation
#!/usr/bin/env python3
macos 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/env python3
RoyalTSX 6.0.1 RTSZ File Handling Heap Memory Corruption PoC
## Exploit Title: Google Chrome Browser 111.0.5563.64 - AXPlatformNodeCocoa Fatal OOM/Crash (macOS)
# Exploit Title: HospitalRun 1.0.0-beta - Local Root Exploit for macOS
# Exploit Title: Fetch Softworks Fetch FTP Client 5.8 - Remote CPU Consumption (Denial of Service)
# Exploit Title: Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)
# Exploit Title: Atlassian Jira Server/Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
# Exploit Title: MacOS 320.whatis Script - Privilege Escalation
# Exploit Title: Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
# Exploit Title: VMware Fusion 11.5.2 - Privilege Escalation
Local Privilege Escalation via VMWare Fusion
The XNU function wait_for_namespace_event() in bsd/vfs/vfs_syscalls.c releases a file descriptor for use by userspace...
Tested on macOS Mojave (10.14.6, 18G87) and Catalina Beta (10.15 Beta 19A536g).
On macOS, when a new mount point is created, the kernel uses checkdirs() to, as
# Exploit Title: Apple macOS 10.15.1 - Denial of Service (PoC)
=== Summary ===
# macOS-Kernel-Exploit
There is a heap overflow in [NSURL initWithCoder:] that can be reached via iMessage and likely other paths. When an N...
# Exploit Title: Code execution via path traversal
Exploit Title: Code execution via path traversal
XNU has various interfaces that permit creating copy-on-write copies of data
There is a memory corruption issue that occurs when processing a malformed RTP video stream in FaceTime. It appears t...
XNU has various interfaces that permit creating copy-on-write copies of data
# Exploit Title: Microsoft Remote Desktop 10.2.4(134) - Denial of Service (PoC)
# Exploit Title: MacOS 10.13 - 'workq_kernreturn' Denial of Service (PoC)
=======================================================================
# Exploit Title: CuteFTP Mac 3.1 Denial of Service (PoC)
There are a variety of problems that occur when processing malformed H264 streams in readSPSandGetDecoderParams, lead...
There is a heap corruption vulnerability in VCPDecompressionDecodeFrame which is called by FaceTime. This bug can be ...
=======================================================================
This PoC file might look familiar; this bug is a trivial variant of CVE-2016-1744 (Apple bug id 635599405.)
# Exploit Title: Apple MacOS 10.13.4 - Denial of Service (PoC)
Charles Proxy is a great mac application for debugging web services and
nvDevice::SetAppSupportBits is external method 0x107 of the nvAccelerator IOService.
# Exploit title: Yosoro 1.0.4 - Remote Code Execution
Here's a kextd method exposed via MIG (com.apple.KernelExtensionServer)
Google software updater ships with Chrome on MacOS and installs a root service (com.google.Keystone.Daemon.UpdateEngine)
AppleEmbeddedOSSupportHost.kext is presumably involved in the communication with the OS running on the touch bar on n...
#!/bin/bash
#!/usr/bin/env ruby
The sysctls vfs.generic.conf.* are handled by sysctl_vfs_generic_conf(), which is implemented as follows:
AppleIntelCapriController::getDisplayPipeCapability reads an attacker-controlled dword value from a userclient structure