logo

An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit

ID: 2ebe8952-a18f-5617-ada1-80e60adbde6d

STIX ID: report--2ebe8952-a18f-5617-ada1-80e60adbde6d

Feed Name: Google Project Zero

Threat Score
90/100

Date Published: 2023-10-13

Date Updated: 2026-07-16

Author: Google Project Zero

...
...

Ian Beer (Project Zero) details an in‑the‑wild iPhone zero‑day chain used in targeted attacks: after a JavaScriptCore code execution primitive, attackers use Safari's IPC to reach the GPU process and exploit a WebGPU RemoteBuffer::Unmap unchecked memcpy to achieve sandbox escape and build arbitrary read/write primitives. The writeup traces heap grooming, object corruption, and escalation into kernel/userclient interactions, then shows how attackers used arbitrary R/W to flip NSExpression/NSKeyedArchiver protections, execute a large serialized payload (including embedded JavaScript), obtain PAC‑signed native function pointers, and install a reusable JS‑implemented IPC backchannel to drive kernel/userclient actions; Apple released fixes (iOS 16.4.1) for related CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.