Exploit Development: Unveiling Windows ARM64 Pointer Authentication (PAC)
ID: 97d270f4-d45d-5322-b5b9-31399941c21b
STIX ID: report--97d270f4-d45d-5322-b5b9-31399941c21b
Feed Name: Connor McGarr’s Blog
This report provides a deep dive into Windows ARM64 Pointer Authentication Code (PAC), detailing how the feature is initialized by the bootloader and kernel, gated by feature flags, and enabled per process with distinct user-mode keys. It explains compiler instrumentation for signing and authenticating return addresses, key rotation across user-kernel transitions, and how Secure Kernel/HyperGuard intercepts unauthorized key changes. The paper demonstrates how PAC violations are handled, methods to query state and policies, and positions PAC as a backward-edge control-flow integrity mitigation on ARM, noting potential future enhancements alongside Memory Tagging Extension.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
