28.11.2014 Views

iOS Kernel Heap Armageddon - Hakim

iOS Kernel Heap Armageddon - Hakim

iOS Kernel Heap Armageddon - Hakim

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Exploiting the freelist in <strong>iOS</strong> 6<br />

• Apple has changed the freelist handling in <strong>iOS</strong> 6<br />

• memory is now tagged with a fixed value<br />

• doesn‘t stop freelist exploitation<br />

• but stops exploitation method used in all public <strong>iOS</strong> heap exploits<br />

Stefan Esser • <strong>iOS</strong> <strong>Kernel</strong> <strong>Heap</strong> <strong>Armageddon</strong> REVISITED • July 2012 •<br />

15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!