corekit-framework

1
quality: all 6+ 8+
8
0

Technical deep-dive into exploiting CVE-2024-54529, a type confusion vulnerability in macOS's coreaudiod system daemon via the Mach messaging service. The author details the exploitation process of converting a crash into a working exploit through creative problem-solving, following their discovery via knowledge-driven fuzzing methodology.

projectzero.google · Dillon Franke, Google Information Security Engineering, 20% time on Project Zero· 2 months ago · exploit · details