Redacted
Title
Tear Down “DarkSword”
Abstract
With the capture of DarkSword, a full iOS one-click attack chain has been publicly exposed for the first time in a long while. The chain is implemented entirely in JavaScript and contains no obfuscation.
This talk breaks down DarkSword piece by piece to provide insight into today’s iOS VR/XD techniques, including implementing a full chain in JSContext, exploiting UAF under JavaScript engine garbage collection, a data-only dlopen primitive, PAC bypass through dyld protected by SPRR, a data-only lock-based hook strategy, gaining AAR/W in GPUProcess, controlling mediaplaybackd through a CoW bypass bug, and using a powerful bug to obtain kernel AAR/W. To prevent weaponization or malicious use, the post-exploitation phase will not be discussed.