iOS Vulnerability Research

Hunt iOS kernel bugs from public firmware to stock-device proof.

This expert track bridges macOS kernel research into iOS: public IPSW analysis, kernelcache carving, sandbox reachability, arm64e handler review, panic triage, proof construction, target-flag evidence, and Apple bounty reporting.

The course is organized around show-then-tell phases. Researchers work Mac-side first, confirm device-side when needed, and learn how to decide which iOS surfaces are worth time before burning cycles on a rabbit hole.

00

Workbench: Splitting Mac-Side and Device-Side

Build the iOS vulnerability research workbench: IPSW acquisition, kernelcache extraction, Mac-side analysis, and stock-device confirmation boundaries.

5 modules
00.1Same Kernel, Harder Playground: Why iOS Research Splits Mac-Side and Device-Side
Locked
00.2Firmware Is Public: Download an IPSW and Extract the iOS Kernelcache
Locked
00.3Reading the iOS Kernelcache on Your Mac: Kexts, Arch, and the Surface
Locked
00.4The Stock Device Side: What a Non-Jailbroken iPhone Will and Will Not Tell You
Locked
00.5Lab: Build Your iOS Workbench End to End
Locked
01

Same XNU, Different Rules

Transfer the right macOS kernel knowledge to iOS while accounting for boot trust, sealed kernels, arm64e heap behavior, KTRR, KPP, and PPL.

5 modules
01.1Same XNU, Different Rules: What Carries Over From macOS and What Does Not
Locked
01.2The iOS Boot and Trust Chain: Why the Kernel You Analyze Is Sealed on the Device
Locked
01.3iOS Memory and the Kernel Heap: Zones on the Phone, and What arm64e Adds
Locked
01.4KTRR, KPP/PPL, and Kernel Protections That Change What a Bug Can Do
Locked
01.5Lab: Diff a macOS and an iOS Kernelcache and Catalog What Is iOS-Only
Locked
02

IOKit User Clients on iOS

Map iOS IOKit from the sandboxed attacker model and decide when a user client is genuinely reachable.

5 modules
02.1IOKit User Clients on iOS: Same Model, Sealed Behind the Sandbox
Locked
02.2The App Sandbox as the Baseline Attacker (Why It Changes the Whole Game)
Locked
02.3The Golden Property: When a Sandboxed App Can Open a Kernel User Client
Locked
02.4Reading Which User Clients an iOS Driver Exposes, From the Kernelcache
Locked
02.5Lab: Find User-Client-Vending Drivers in the iOS Kernelcache and Rank by Sandbox Reachability
Locked
03

Two-Sided Surface Mapping

Join kernelcache evidence with device-side probing to produce a defensible reachability verdict.

5 modules
03.1Two-Sided Surface Mapping on iOS: Kernelcache on the Mac, Probe on the Device
Locked
03.2Enumerating iOS User Clients by Provider, Not Class Name (and Why)
Locked
03.3Reading the Entitlement and Sandbox Gates in the iOS Kernelcache
Locked
03.4The iOS Reachability Verdict: Sandbox-Open, Entitlement-Walled, or Not-Present
Locked
03.5Lab: Build a Sandbox Reachability Probe and Run It on the Simulator/Device
Locked
04

ARM64e and Reading iOS Kernel Code

Read arm64e dispatch paths, handlers, attacker-controlled input, entitlement gates, sandbox checks, and PAC-shaped tells in real iOS kernel code.

5 modules
04.1arm64e vs arm64: Reading PAC-Signed Pointers in Real iOS Disassembly
Locked
04.2Carving a Kext and Finding Its Dispatch and Handlers on iOS
Locked
04.3Following Attacker Input to a Sink in a Real iOS Driver
Locked
04.4The iOS Tells in Disassembly: Entitlement Checks, Sandbox Checks, PAC Gadgets
Locked
04.5Lab: Annotate a Real iOS Kext Handler to a One-Sentence Verdict
Locked
05

Kernelcache Reverse-Engineering Workflow

Run the practical kernelcache loop: carve kexts, rebuild dispatch, follow sinks, inspect public bug classes, and drive selectors to verdicts.

5 modules
05.1Find the Dispatch Table in a Carved iOS Kext (Reconstruct the Descriptor)
Locked
05.2Follow Input to a Sink and Walk Up the Call Graph on iOS
Locked
05.3Working at Kernelcache Scale: Carving, Byte-Pattern Search, and the iOS Slide
Locked
05.4Real iOS Observation: Read a Public, Patched iOS Kernel Bug Class
Locked
05.5Lab: Full RE Pass on a Real iOS Kext Selector, From Dispatch to Verdict
Locked
06

Target Selection and Lead Triage

Turn a large iOS surface into a small set of workable leads by ranking reachability, impact, bug class, and evidence quality.

5 modules
06.1The iOS Threat Model Is a Sandboxed App: Define It and Match Your PoC
Locked
06.2The iOS Reachability Chain and the Cost of Confirming It
Locked
06.3The iOS Rabbit Holes and How to Detect Each Early
Locked
06.4Ranking iOS Candidates From a Real Kernelcache Scan
Locked
06.5Lab: Triage a Real iOS Candidate Set Down to One Target
Locked
07

Memory-Safety Bug Classes

Model iOS-shaped bounds, length, count, index, and copy bugs with small proof harnesses and real kernel reading discipline.

5 modules
07.1The One-Sentence Shape, and Multiplication Overflow to Undersized Allocation
Locked
07.2Missing and Oversized Length Bounds on Copies: the Read-Before-Check OOB Tell
Locked
07.3Integer Underflow, Signedness, and the Value That Walks Backward
Locked
07.4Out-of-Bounds Indexing, Read vs Write, and What MTE Changes
Locked
07.5Lab: Find and Confirm a Memory-Safety Bug (Bespoke iOS-Shaped Target)
Locked
08

Races and Use-After-Free

Study close-vs-call windows, double fetches, reference lifetime mistakes, and race triage with reproducible stand-ins.

5 modules
08.1Why UAF and Races Beat Bounds Bugs, and the Close-vs-Call Window on iOS
Locked
08.2The Double-Fetch: Shared Memory Between App and Kernel, the Re-Read Tell
Locked
08.3Refcount Errors and Triaging a Race/UAF Crash on iOS
Locked
08.4Winning the Window: Widening, Hammering, and the iOS Heap Reality
Locked
08.5Lab: Win a Close-vs-Call Race (an iOS-Shaped Multithreaded Simulator)
Locked
09

Logic Bugs and Confused Deputies

Analyze iOS privileged services, entitlement borrowing, identifier confusion, and chains that turn daemon authority into kernel reachability.

5 modules
09.1Logic Bugs on iOS and Privileged-Daemon XPC as an Attack Surface
Locked
09.2The Confused Deputy on iOS: a Sandboxed App Borrowing a Daemon's Power
Locked
09.3Entitlement Delegation, Identifier/Path Confusion, and the Network+Entitled-UC Chain Shape
Locked
09.4Enumerating iOS Daemons and Their Entitlements From the Device and Dyld Cache
Locked
09.5Lab: Map iOS Daemon XPC Surface and Demonstrate a Confused-Deputy Shape
Locked
10

Crash, Panic, and Exploitability Triage

Read iOS crash and panic shape, de-slide faulting PCs, decode ESR, and separate meaningful exploitability from noise.

6 modules
10.1The iOS Crash-Report Pipeline: Collecting .ips Panics From a Stock Device
Locked
10.2Anatomy of an iOS Kernel Panic: Fault Address, Registers, Slide
Locked
10.3The Fault Address Decides a Lot: NULL, Page-Aligned, Attacker-Scaled (and Apple's NULL-far Rejection)
Locked
10.4De-Sliding on iOS: From Panic PC to a Function in the Kernelcache
Locked
10.5The Assertion Trap and the iOS Exploitability Rubric
Locked
10.6Lab: Triage iOS Panics to a Verdict Each
Locked
11

Proof, Reproducibility, and Report Evidence

Build proof packages that survive reviewer scrutiny: reproducibility rate, minimal trigger, panic bundle, and control-side evidence.

5 modules
11.1What a Proof Must Prove on iOS: Reachability, Control, Primitive, Reliability
Locked
11.2Honest About the Ceiling: Why Precise Partial Control Beats Vague Claims
Locked
11.3Minimal Reproduction on iOS, Environment Pinning, and Reproduction Rate
Locked
11.4Packaging the iOS Evidence Bundle (PoC, Preflight, Panic .ips, Version Match)
Locked
11.5Lab: Turn an iOS Finding Into a Reproducible Proof Bundle
Locked
12

Apple Submission Workflow

Prepare bounty-grade submissions, deduplicate variants, handle severity disputes, and keep long-running research portfolios clean.

5 modules
12.1The Apple Security Bounty for iOS: Categories, Tiers, and What Gets Paid
Locked
12.2The Anatomy of an iOS Report That Reproduces on the First Try
Locked
12.3The iOS-Specific Evidence: Sandbox-Reachability Proof, Device Plus Version, Panic .ips
Locked
12.4Addenda, Duplicates, Severity Disputes, and the Long Game
Locked
12.5Lab: Write a Full iOS Report From a Bespoke Finding and Self-Review It
Locked
13

Target-Flag Proof and Control-Side Evidence

Understand target-flag style proof, commpage values, control-side distinction, and why a register capture is not automatically impact.

6 modules
13.1What the Target Flag Is and Why Apple Requires It
Locked
13.2The Three Tiers and the Bounty Table
Locked
13.3The Rotation Technique: Landing the KERN_VALUE in a Register Despite Offset Loads
Locked
13.4The Disqualification Traps: NULL-Far, Control-Side vs Data-Side, Per-Boot-Random
Locked
13.5Engineering and Proving a Target-Flag Crash
Locked
13.6Lab: Read the Real Commpage KERN_VALUE and Demonstrate the Control-Side Principle
Locked
14

Signing, Deployment, and Probe Apps

Build signed probe apps, understand sandbox profiles, deploy to simulator or device, and collect structured reachability results.

5 modules
14.1Why Code Signing Changes Your Harness, Not Your Bug
Locked
14.2Free-Signing a Minimal Probe App and Deploying It (Simulator, and Stock Device When Needed)
Locked
14.3The App Sandbox Profile: What Your Probe App Is Allowed to Do
Locked
14.4Structuring a Probe App to Emit Machine-Readable Results
Locked
14.5Lab: Build, Sign, Deploy, and Collect Results From an On-Device Probe
Locked
15

PAC and Memory-Tagging Reality

Read pointer-authenticated dispatch, PAC instruction families, mitigation posture, and the absence or presence of tagging clues.

5 modules
15.1Pointer Authentication in Depth: Signing Keys, Contexts, and the Instruction Family
Locked
15.2What PAC Breaks: Return-Address, Vtable, and Function-Pointer Corruption on iOS
Locked
15.3Memory Tagging in Depth: Tags, Tag Checks, and Where It Is (and Isn't) on iOS
Locked
15.4What PAC and MTE Change for Finding Bugs vs Exploiting Them
Locked
15.5Lab: Read PAC and (Where Present) Tag-Check Instructions in the iOS Kernelcache
Locked
16

Graphics, Media, and Accelerator Surfaces

Map iOS graphics, media, and accelerator attack surfaces from real kernelcache evidence and parser bug classes.

5 modules
16.1The iOS Graphics/Media Kernel Surface: What a Sandboxed App Reaches and Why It's the Richest Target
Locked
16.2IOGPU and the Accelerator Family: The Command-Submission Model and the TOCTOU/Double-Fetch Class
Locked
16.3Media Decoders: The Parse-Attacker-Bytes Surface and the Unchecked-Size / OOB Class
Locked
16.4ANE / Neural Direct-Path: The H11ANE User Client, Program-Descriptor Submission, and the Validation-Gate Reality
Locked
16.5Lab: Carve a Graphics/Media Kext, Map Its Dispatch, and Take One Handler to a Reachability-and-Risk Verdict
Locked
17

Networking and Zero-Click Chains

Study networking reachability, remote parser classes, kernel UC intersections, and the shape of multi-bug iOS chains.

5 modules
17.1The Remote-Reachable iOS Kernel Surface and Why Zero-Click Pays Most
Locked
17.2Finding the Zero-Click Daemons: Network-Facing Processes That Hold Kernel-UC Entitlements
Locked
17.3The Remote Parser Bug Class: Attacker Bytes Off the Wire Into a Kernel Parser
Locked
17.4The Two-Bug Chain in Practice: Remote RCE to Entitled Kernel UC to Target Flag
Locked
17.5Lab: Map the Network+Entitled-UC Intersection and Drive One Chain Candidate to a Verdict
Locked
18

iOS-Only Hardware Drivers

Map baseband, AOP, sensors, NFC, haptics, provider gates, hardware nodes, and entitlement walls.

5 modules
18.1The iOS-Only Hardware Driver Surface: Baseband, AOP/Sensors, NFC, Haptics, Pearl
Locked
18.2Coprocessor Shared-Memory Queues: the Ring/Descriptor Pattern (AOP, Baseband)
Locked
18.3NFC / Stockholm and Short-Range Radio: the Controller UC Surface and Reachability
Locked
18.4The Hardware-Gated Wall: How to Tell Reachable From Gated in Minutes
Locked
18.5Lab: Carve One iOS-Only Hardware Kext and Produce Its Reachability Verdict
Locked
19

Filesystems and Mountable Media

Separate real iOS kernel-resident filesystem surface from desktop assumptions and analyze on-disk parser bug classes.

5 modules
19.1On-Disk Parsers as a Kernel Surface, and the iOS Mount Constraint
Locked
19.2The On-Disk-Structure Bug Class: Length, Count, and Continuation Fields Trusted From Disk
Locked
19.3Carving and Reading a Real iOS Filesystem Driver: the Mount Path and the Parse Loop
Locked
19.4iOS Mount Reachability: DMG, LiveFS, and the Confused-Deputy-Holds-a-Mount-Entitlement Pattern
Locked
19.5Lab: Carve a Real FS Kext, Locate Its On-Disk Parse Entry, and Produce a Reachability + Risk Verdict
Locked
20

Security Subsystems and Kernel Policy

Analyze AMFI, sandbox, keystore, trust caches, and MAC policy enforcement as real iOS kernel attack surfaces.

5 modules
20.1The iOS Security-Subsystem Surface and the Golden Property
Locked
20.2AppleSEPKeyStore Up Close: The Dispatch Surface and the SEP Mailbox Shim
Locked
20.3The Entitlement-Bitmap-Gated Dispatch Pattern (and How You Map the Reachable Selectors)
Locked
20.4AMFI, Codesign, and Sandbox as Kernel Policy (Where They Enforce, and the Mitigation-Bypass Value)
Locked
20.5Lab: Carve a Security Kext, Map Its Selector Surface, and Produce the Reachability Verdict
Locked
21

User-to-Privileged iOS Deputies

Map daemon protocols, entitlement borrowing, deputy chains, and routes from unprivileged input to privileged kernel opens.

5 modules
21.1The iOS Confused-Deputy Field: User to Privileged Without a Memory Bug
Locked
21.2Finding the Deputies: Enumerate Root Daemons, Reachable XPC Services, and Entitlements
Locked
21.3The dlopen Introspection Technique: Read a Daemon's Protocol, Methods, and Entitlement Gate
Locked
21.4The Pivot to Kernel: a Deputy That Opens a Caller-Supplied User Client
Locked
21.5Lab: Take a Real iOS Deputy Candidate to a Confused-Deputy Verdict
Locked
22

Coprocessor and Secure-World Boundaries

Understand where the kernel ends: SEP, baseband, AOP, DART, DMA descriptors, and boundary bug classes.

5 modules
22.1Where the Kernel Ends: Baseband, SEP, AOP, and the Coprocessor Boundary
Locked
22.2The DMA Boundary: SART, DART, and the Coprocessor-Descriptor Bug Class
Locked
22.3The SEP Mailbox: Endpoints, Out-of-Line Buffers, and Unpacking an Enclave Reply
Locked
22.4Exclaves: The Secure World Moving Out of XNU, and What That Does to the Surface
Locked
22.5Lab: Carve a Coprocessor Boundary Driver and Take It to a Reachability Verdict
Locked
23

Capstone: Full iOS Kernel Research Workflow

Run the whole workflow on a fresh target: carve, map, reason, prove, and write a verdict-quality finding package.

5 modules
23.1The Capstone Brief: Run the Whole Workflow on a Fresh Target
Locked
23.2Carve and Reconstruct: The IOSurface Dispatch Surface
Locked
23.3Follow the Data Flow and Check the Guard
Locked
23.4Write the Verdict and the Finding Template
Locked
23.5Lab: Your Solo Capstone, a Fresh Target From Kernelcache to Verdict
Locked