Splitting atoms in XNU
googleprojectzero.blogspot.com
googleprojectzero.blogspot.com
Yep.
> How often does discovery or research like this lead to a dead end?
Orders of magnitude more than the successful paths these days.
I'd recommend the Security Now podcast by Steve Gibson if you're interested in this sort of thing. He does a great job explaining many of the exploits out there.
https://motherboard.vice.com/en_us/article/qvapxq/apple-ipho...
I'm guessing the salary must be higher than the rewards or they wouldn't do it tho.
[…]
This is trying to detect whether another thread acquired and dropped the lock while this thread dropped it then reacquired it. If so, the code checks whether there's still a vm_map_entry covering the current address its trying to copy and then bails out and looks up the entry again.”
I find that disconcerting. Apparently, the writers of this didn’t have a clear model of what locks are needed where, or (worse) they had a model, but knew it didn’t work.
Anybody writing that code should have seen this coming.
The trick is you have to assume everything changed under you when you dropped the lock, and recheck everything
Props to Project Zero. There's some seriously talented people on than crew.
At first I thought this was a convoluted HalfLife reference https://half-life.fandom.com/wiki/Xen
I would treat any code allocating / deallocating / moving / locking memory by hand instead of using higher level constructs unsafe now that we know that it's possible to automate checking safety of the operations.
https://www.theverge.com/2018/11/28/18115264/google-fi-iphon...