logo

Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages

ID: ba92214d-4503-50c8-a4ca-31ff72859308

STIX ID: report--ba92214d-4503-50c8-a4ca-31ff72859308

Feed Name: Google Project Zero

Threat Score
70/100

Date Published: 2025-05-09

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

Google Project Zero researcher describes discovery and exploitation of a type‑confusion vulnerability in macOS CoreAudio's Mach IPC handlers (com.apple.audio.audiohald) that allowed sandbox escapes and potential arbitrary code execution; the post details the fuzzing harness, reverse engineering, PoC, and Apple patches (CVE‑2024‑54529) shipped in recent macOS updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.