MTE as a microscope
ID: 1b4a2ff3-f229-5439-83ec-699b16cf5216
STIX ID: report--1b4a2ff3-f229-5439-83ec-699b16cf5216
Feed Name: Jamf Blog
This report explains ARM MTE and Apple’s MIE implementation, details how hardware memory tagging works (tags in pointers and Tag RAM), and presents a case study where MIE's synchronous tag checks exposed a race-condition-induced use-after-free in the iOS kernel that would be invisible on non-MTE devices. The authors argue MTE/MIE not only mitigates exploitation but acts as a microscope for discovering latent kernel bugs, describe Apple’s enhancements (EMTE and TCE), contrast deployment choices (synchronous vs asynchronous), and outline implications for researchers, defenders, and attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
