MDOYVR25 - Csaba Fitzl – Finding Vulnerabilities in Apple packages at Scale
Автор: MDOYVR
Загружено: 2025-06-21
Просмотров: 202
MacDevOpsYVR 2025 Conference
MDOYVR25
Csaba Fitzl
Finding Vulnerabilities in Apple packages at Scale
This talk I will show how I automated the vulnerability research
across the packages, and how I used ChatGPT to help me with that. I
will show the process which allowed me to trim down the research from
10.000 to about 300 packages, which allowed me to quickly go through
each package.
I will disclose five previously unpublished vulnerabilities, which I
found during my research. All these vulnerabilities allowed me to
bypass SIP’s file system protection, what I could use to persist
anything with SIP protection (so regular AVs can’t clean up the files)
or bypass TCC.
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: