TrAz5r's profile picture.

Clean COW

@TrAz5r

Clean COW reposted

🧵Apple just devalued full TCC bypasses from 30,5k to 5k. Hard to interpret this in a good way. It feels like - we admit we can’t fix this shit and we don’t care or at least not willing to pay for it - we don’t care about privacy security.apple.com/bounty/categor…


Clean COW reposted

Writeup of TaskPortHaxxApp is now available with all the info of how we made iOS 17.0 semi jailbreak possible, including details of userspace PAC bypass that works everywhere TrollStore 2 is available (should I name it TrollPAC?) github.com/khanhduytran0/…


Clean COW reposted

So, apparently you can SSL strip many Apps on macOS, getting tokens and maybe sensitive user information - in my case, I did @claudeai desktop 👀 A vulnerability? Probably not, but still useful for attackers. github.com/yo-yo-yo-jbo/s…


Clean COW reposted

Happy Saturday! Videos from #OOTB2025BKK are out on the HITB Youtube channel - youtube.com/playlist?list=…


Clean COW reposted

Since #Microsoft does not care, and the grace period is over, here is the Hardened Runtime bypass they introduced through .NET MAUI on #macOS. All applications built with it are vulnerable. The #vulnerability has existed probably since 2019. afine.com/breaking-harde…


Clean COW reposted

Highly recommend reading this great article by @JamfSoftware😍 jamf.com/blog/chillyhel… Some IOCs (see the write-up for the full list 😉): - Mach-O: 6a144aa70128ddb6be28b39f0c1c3c57d3bf2438 - Team IDs: R868N47FV5, F645668Q3H - IPs: 93[.]88[.]75[.]252, 148[.]72[.]172[.]53


Clean COW reposted

🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-in…


Clean COW reposted

It is probably the weirdest way I've found a stack overflow #vulnerability until now (patched in 15.6). Here is a blog post for those interested in #IOKit #macOS #kernel or #Apple Silicon #Exploit Development masochist looking for a target. Enjoy! afine.com/a-mouse-move-t…


Clean COW reposted

New Blog: CVE-2025-24103 : General TCC Bypass imlzq.com/apple/macos/tc…


Loading...

Something went wrong.


Something went wrong.