Exploring the world with my sword of debugger : )

Pinned Tweet
Love the gifts from @Apple Product Security! ❤️❤️❤️
18
23
1,236
68,421
Cool 👍
🍎🐛 I got Claude making this, maybe it's useful for others as well. Every Apple security advisory since 2002 - parsed, indexed, charted. With links to writeups, POCs and presentations. apple-cve.com/
1
13
3,661
In the AI era, the list will be updated frequently. I’m gradually stepping back to devote myself fully to my new baby.
6
183
Mickey Jin retweeted
I got the latest iOS and macOS 27 booting in Qemu (with SPTM!) - Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac supported - Debug, patch, or modify everything: kernel, SPTM, TXM, launchd, dyld, user programs all modifiable/ GDB-able - Boots directly to root shell in seconds - Run your own programs as root in iOS/ macOS, no jailbreak / kernel patches required - SPTM, TXM, MTE/MIE, genter/ gexit, GXF/SPRR/GL0-2, AMCC, AIC v1-3, Apple timer, many sysregs - Automated setup; get running in just a few minutes - Runs anywhere qemu runs... no ARM CPU required 😉 Try it here: github.com/jprx/darwin-vm
41
387
2,684
289,873
Empty vessels make the most noise. Barking dogs seldom bite.
CVE-2026-28910 just saw the CVE information has been updated. Im the first one who found this vulnerability, on 5/8/25, five months before you did. And the impact was underestimated, it could do more things than your PoC.Easily weaponized. Keep calm. Your post made it sound like I had stolen your research. If you wanna verify the timing of other reports, DM them instead of doing something like this. Not geeky.
2
30
4,651
they patched this vulnerability just because i gave them a weaponizable PoC, no need any user interaction. the patch is not finished, won't disclose at this moment
Replying to @patch1t
Dragging and dropping a file only gave access to one specific file and folder, plus it’s obvious that if you drag and drop a file, the target application will have access to it. With Archive Utility’s plist, the attacker would’ve had unrestricted and persistent access to any file on the system, including hijacking apps Anyway, we can agree to disagree. Apple considered it a real vulnerability and fixed it.
1
7
3,993
That makes sense now.
Replying to @mysk_co
This one is similar to my CVE-2026-20633, patched in macOS 26.4 too. However, my bug doesn’t require any user interaction. I can’t disclose the details right now because I have already submitted a bypass report 🫣
1
4
960
I finally got around to blogging about this, and a separate bug (CVE-2024-44219). If you're interested in homedir TCC protections, enforcement via `sandboxd` or the sandbox kernel extension, I'd be pleased if you took a quick look! rdowd.com/castles-made-of-sa…
I doubt that I was the first to find this quirky bug, however the impact of basically having tccd fail open was very easy to overlook. Remains unpatched in Ventura and Sonoma unfortunately.
5
9
48
8,871
Nice research, congrats!
1
2
233
Mickey Jin retweeted
The screensharingd bug is a pre-auth, and an amazing bug that LLM enabled clowns killed without understanding it. Releasing a PoC that allows to download files from vulnerable macOS. It’s not super reliable, but the real one is very much. Patch asap! reverse.put.as/2026/07/29/it…
9
34
188
67,588
After reading @lateralusd_ blog: ns-echo.com/posts/cve_2023_4… I found the same bug that you found here, and then I reported to the ZDI. Finally, it was disclosed as 0-day: zerodayinitiative.com/adviso…
2
12
495
Mickey Jin retweeted
🍎🌁 Big changes to user TCC.db in macOS Golden Gate! It seems that it finally got the protection it deserves. It was moved to: /private/var/containers/Data/ProtectedSystem/[UUID]/Data/Library/Application Support/com.apple.TCC/ You can't access it even with FDA, and likely need "com\.apple.private.security.protected-system-container" entitlement to write to it.
3
23
95
12,880
Mickey Jin retweeted
Replying to @theJoshMeister
IMO Mysk is not trustworthy. They tried to hype low impact vulns as critical in the past (HTTP icon download). Also... duplicates happen, and Apple always credits you for those. If you can't trust the vendor's decision about first submitter, then don't submit. I did cross check a few of these duplicates with researchers in the past, and Apple was always right.
1
2
16
1,401
Coincidentally, several researchers who find Apple vulnerabilities have been posting this week about giving up on trying to work with the Apple Security Bounty program. (🧵)
Chat, I don't want to be that guy, but I think Microsoft has really pissed off security researchers and we're approaching the tipping point. This Eclipse guy has really rocked the boat for Microsoft.
4
8
69
7,669
IMO Mysk is not trustworthy. They tried to hype low impact vulns as critical in the past (HTTP icon download). Also... duplicates happen, and Apple always credits you for those. If you can't trust the vendor's decision about first submitter, then don't submit. I did cross check a few of these duplicates with researchers in the past, and Apple was always right.
1
2
16
1,401
Yes, agreed. I don’t think mysk’s report is a real vulnerability.
Replying to @patch1t @mysk_co
The CVE-2026-28910 requires the access to a protected plist file first, this shouldn’t be considered as a real vulnerability, in my humble opinion.
1
4
207
📝🚨 New blog post: How a bug in Archive Utility allowed access to protected app data (including iMessage and WhatsApp chats, and Safari cookies) without any permissions. The bug could also be exploited to hijack installed apps such as Signal and 1Password to perform phishing attacks. Apple fixed the issue in macOS 26.4 as CVE-2026-28910, five months after we reported it. mysk.blog/2026/05/19/cve-202…
5
33
442
189,656
We did showcase how a user could easily be tricked into granting the attacker permanent and persistent access to the plist file without them realising it, or any way of revoking access So in our humble opinion, we consider it a real vulnerability ;)
1
425
Maybe the trick of social engineering is the vulnerability here. But you can get access to any protected file (not only the plist file) by convincing the victim to drag&drop.
1
1
331
Replying to @mysk_co
This one is similar to my CVE-2026-20633, patched in macOS 26.4 too. However, my bug doesn’t require any user interaction. I can’t disclose the details right now because I have already submitted a bypass report 🫣
1
1
15
2,749
The CVE-2026-28910 requires the access to a protected plist file first, this shouldn’t be considered as a real vulnerability, in my humble opinion.
1
4
876
Received my first Apple Bounty in my life! Couldn’t check the status in real time, but now I can 🙂
21
1
182
22,508
Congrats!
1
3
440
My first CVE! 🎉🎉🎉 This is my non-write-up blog post about it: blog.reversesociety.co/blog/…
10
12
129
9,076
Congrats!
1
2
181
Love the gifts from @Apple Product Security! ❤️❤️❤️
18
23
1,236
68,421
That would be a dream 😍 Are you directly at apple or are you a partnered security researcher?
1
1
1,422
Independent researcher
328
Mickey Jin retweeted
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/p…
7
231
1,012
117,953