Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1728Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582) Arbitrary file write Apple Richard Warren (@buffaloverflow) Bug Bounty2022-03-152023-06-13
1709Targeting Visual Studio Code for macOS: File Discovery and a TCC bypass (kinda) Local Privilege Escalation TCC bypass MacoS Apple Microsoft Alfie Champion (@ajpc500) Bug Bounty2022-03-212023-06-13
1664MacOS SUHelper Root Privilege Escalation Vulnerability: A Deep Dive Into CVE-2022-22639 Local Privilege Escalation Apple Mickey Jin (@patch1t) Bug Bounty2022-04-042023-06-13
1406Get root on macOS 12.3.1: proof-of-concepts for Linus Henze%27s CoreTrust and DriverKit bugs (CVE-2022-26766, CVE-2022-26763) Signature validation bypass Memory corruption Local Privilege Escalation MacOS Apple Zhuowei Zhang (@zhuowei) Bug Bounty2022-07-022023-06-13
1371Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706 Local Privilege Escalation Apple Microsoft 365 Defender Research Team Bug Bounty2022-07-132023-06-13
1313CVE-2022-26712: The POC for SIP-Bypass Is Even Tweetable MacOS SIP bypass Apple Mickey Jin (@patch1t) Bug Bounty2022-07-262023-06-13
1241Process injection: breaking all macOS security layers with a single vulnerability Local Privilege Escalation Process injection vulnerability Apple Thijs Alkemade (@xnyhps) Bug Bounty2022-08-122023-06-13
901SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri iOS MacOS Bluetooth Local Privilege Escalation TCC bypass Apple Guilherme Rambo (@_inside) Bug Bounty2022-10-262023-06-13
883A tale of a simple Apple kernel bug Out-of-bounds Read Memory corruption MacOS iOS Apple Jordy Zomer (@pwningsystems) Bug Bounty2022-10-312023-06-13
861CVE-2022-26730 | ColorSync | Hoyt LLC MacOS Memory corruption RCE Apple David Hoyt (@h02332) Bug Bounty2022-11-052023-06-13
837CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS MacOS Local Privilege Escalation SIP bypass Apple Mickey Jin (@patch1t) Bug Bounty2022-11-112023-06-13
833CVE-2022-32929 - Bypass iOS backup%27s TCC protection Local Privilege Escalation TCC bypass MacoS iOS Apple Csaba Fitzl (@theevilbit) Bug Bounty2022-11-142023-06-13
810macOS Sandbox Escape vulnerability via Terminal MacOS Sandbox escape Local Privilege Escalation Apple Wojciech Reguła (@_r3ggi) Bug Bounty2022-11-182023-06-13
713Public Report – VPN by Google One Security Assessment Android iOS DoS Windows MacoS Local Privilege Escalation Google Daniel Romero (@daniel_rome) Bug Bounty2022-12-092023-06-13
681Gatekeeper’s Achilles heel: Unearthing a macOS vulnerability Local Privilege Escalation GateKeeper bypass Apple (macOS) Jonathan Bar Or (@yo_yo_yo_jbo) Bug Bounty2022-12-172023-06-13
672Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities MacOS Local Privilege Escalation SIP bypass Apple (macOS) Mickey Jin (@patch1t) Bug Bounty2022-12-202023-06-13
670A Technical Analysis of CVE-2022-22583 and CVE-2022-32800 MacOS Local Privilege Escalation SIP bypass Apple (macOS) Mickey Jin (@patch1t) Bug Bounty2022-12-212023-06-13
600SSD Advisory – MacOS Mozilla Firefox Download Protections Were Bypassed By .atloc / .ftploc Files Local Privilege Escalation Mozilla (Firefox) Dohyun Lee Bug Bounty2023-01-112023-06-13
597DER Entitlements: The (Brief) Return of the Psychic Paper iOS MacOS Local Privilege Escalation Apple Ivan Fratric (@ifsecure) Bug Bounty2023-01-122023-06-13
595Bad things come in large packages: .pkg signature verification bypass on macOS Local Privilege Escalation GateKeeper bypass SIP bypass MacOS Apple Sector 7 (@sector7_nl) Bug Bounty2023-01-132023-06-13
460CVE-2022-22655 - TCC - Location Services Bypass MacoS TCC bypass Apple (macOS) Csaba Fitzl (@theevilbit) Bug Bounty2023-02-132023-06-13
422Trellix Advanced Research Center Discovers a New Privilege Escalation Bug Class on macOS and iOS Local Privilege Escalation Apple (macOS) Austin Emmitt (@alkalinesec) Bug Bounty2023-02-212023-06-13
356Bypass TCC via iCloud TCC bypass Local Privilege Escalation Apple (macOS) Wojciech Reguła (@_r3ggi) Bug Bounty2023-03-042023-06-13
338Feeding Tasty Objects to Visual Studio%27s App Center SDK for Apple Insecure deserialization MacOS Microsoft Jenny (@OldM4nHunting) Bug Bounty2023-03-072023-06-13
224Bash Privileged-mode Vulnerabilities In Parallels Desktop And CDPATH Handling In MacOS MacoS Local Privilege Escalation Parallels Reno Robert (@renorobertr) Bug Bounty2023-04-062023-06-13