Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
ID: fb16d33b-c4f9-52ce-88a1-4bea921aadbf
STIX ID: report--fb16d33b-c4f9-52ce-88a1-4bea921aadbf
Feed Name: GBHackers
A recently disclosed integer-underflow bug in Apple’s modern Mach-O archive parser (affecting ld-prime, libtool, ranlib and related tools used by Xcode/Command Line Tools) allows a maliciously crafted static library (.a) to cause deterministic crashes, aborts, or out-of-bounds reads that can print adjacent process memory to build logs. The flaw stems from trimming trailing spaces in a 16-byte archive filename when an unsigned index underflows and wraps, producing a corrupted string length; researchers demonstrated the issue with small crafted archives and warned of supply-chain and CI risks while Apple had not published a public advisory at the time of the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
