An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
ID: 2ebe8952-a18f-5617-ada1-80e60adbde6d
STIX ID: report--2ebe8952-a18f-5617-ada1-80e60adbde6d
Feed Name: Google Project Zero
Ian Beer (Project Zero) details an in‑the‑wild iPhone zero‑day chain used in targeted attacks: after a JavaScriptCore code execution primitive, attackers use Safari's IPC to reach the GPU process and exploit a WebGPU RemoteBuffer::Unmap unchecked memcpy to achieve sandbox escape and build arbitrary read/write primitives. The writeup traces heap grooming, object corruption, and escalation into kernel/userclient interactions, then shows how attackers used arbitrary R/W to flip NSExpression/NSKeyedArchiver protections, execute a large serialized payload (including embedded JavaScript), obtain PAC‑signed native function pointers, and install a reusable JS‑implemented IPC backchannel to drive kernel/userclient actions; Apple released fixes (iOS 16.4.1) for related CVEs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
