🍎🐛 I got Claude making this, maybe it's useful for others as well.
Every Apple security advisory since 2002 - parsed, indexed, charted. With links to writeups, POCs and presentations.
apple-cve.com/
I got the latest iOS and macOS 27 booting in Qemu (with SPTM!)
- Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac supported
- Debug, patch, or modify everything: kernel, SPTM, TXM, launchd, dyld, user programs all modifiable/ GDB-able
- Boots directly to root shell in seconds
- Run your own programs as root in iOS/ macOS, no jailbreak / kernel patches required
- SPTM, TXM, MTE/MIE, genter/ gexit, GXF/SPRR/GL0-2, AMCC, AIC v1-3, Apple timer, many sysregs
- Automated setup; get running in just a few minutes
- Runs anywhere qemu runs... no ARM CPU required 😉
Try it here: github.com/jprx/darwin-vm
CVE-2026-28910 just saw the CVE information has been updated. Im the first one who found this vulnerability, on 5/8/25, five months before you did. And the impact was underestimated, it could do more things than your PoC.Easily weaponized. Keep calm. Your post made it sound like I had stolen your research. If you wanna verify the timing of other reports, DM them instead of doing something like this. Not geeky.
The screensharingd bug is a pre-auth, and an amazing bug that LLM enabled clowns killed without understanding it. Releasing a PoC that allows to download files from vulnerable macOS. It’s not super reliable, but the real one is very much. Patch asap!
reverse.put.as/2026/07/29/it…
🍎🌁 Big changes to user TCC.db in macOS Golden Gate! It seems that it finally got the protection it deserves.
It was moved to:
/private/var/containers/Data/ProtectedSystem/[UUID]/Data/Library/Application Support/com.apple.TCC/
You can't access it even with FDA, and likely need "com\.apple.private.security.protected-system-container" entitlement to write to it.
IMO Mysk is not trustworthy. They tried to hype low impact vulns as critical in the past (HTTP icon download). Also... duplicates happen, and Apple always credits you for those. If you can't trust the vendor's decision about first submitter, then don't submit. I did cross check a few of these duplicates with researchers in the past, and Apple was always right.
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices.
projectzero.google/2026/01/p…
🎉 A decade of Mac malware research 🎉
Just published our 10th annual “The Mac Malware of <year>” report ...2025 edition!
For each new sample of 2025, covers:
🔎 IoCs 💉 Infection 💾 Persistence 📡 Capabilities ☣️ Samples for download
Dive in 👇
objective-see.org/blog/blog_…
Introducing DirtyDict. A series of vulnerabilities found by me and @patch1t.
Most of this is my perspective, but Mickey did give me permission to share some details about one of his bugs.
Enjoy!
wts.dev/posts/dirtydict/
🎉 My new blog post is about a PackageKit vulnerability I learned from @p1tsist1p 's blog posts.
🍎🐛macOS LPE via the .localized directory
I tried convincing Apple to universally fix it with no luck.
Go hunt for vulnerable pkg installers! There is a ton :-( Happy Friday!
theevilbit.github.io/posts/l…
The slidedeck to our talk, Crash One: A Starbucks Story - CVE-2025-24277, with @gergely_kalman from @hexacon_fr and @objective_see#OBTS is available from the link below.
It was a macOS vulnerability impacting the crash reporting process where we could achieve LPE and sandbox escape.
theevilbit.github.io/talks_w…
Excited to share our research on ChillyHell, a modular macOS backdoor targeting officials in Ukraine. Check out our write-up for more details.
jamf.com/blog/chillyhell-a-m…
A tiny timing flaw in Apple’s core file-copy APIs can put millions of devices at risk 📂🍏
Despite warnings, Apple thought it was “too hard to exploit”—until Mickey Jin developed an exploit that steals secrets in privileged services
👉nullcon.net/berlin-2025/spea…#NullconBerlin2025