This is interesting theoretically but the amount of access required is pretty high, this is hardly an exploitable zero day.
Having read the paper, in a nutshell it requires:
- Login to the Mac in question
- Ability to install a custom kext to make the PACMAN Gadget work. The exploit requires access to undocumented registers on the M1 that are apparently not accessible from user space, but this is a bit unclear.
- Also need an exploitable kernel buffer overflow against Mac OS (they made a custom kext with a buffer overflow)
- Run the bufferflow + Pacman Gadget together to do the final elevation
If someone can find a way to do this without installing kexts then it becomes way more serious. As is it certainly is a super interesting paper and presents a bunch of work for chip designers.