Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-8540 PoC — 多款Apple产品Kernel组件安全漏洞

Source
Associated Vulnerability
Title: 多款Apple产品Kernel组件安全漏洞 (CVE-2019-8540)
Description:A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
Description
Kernel Stack info leak at exportObjectToClient function
Readme
# CVE-2019-8540
Kernel Stack info leak at exportObjectToClient function

 bug details:
 
 macOS<=10.14.3 && iOS < 12.2
 
 
There is a bug at Function exportObjectToClient  in  IOKit class, which can lead to  leak 4 bytes of kernel stack info.
exportObjectToClient  just like its name which make an arbitrary OSObject available to the client task.It’s a basic  function, many other kernel  function use it .

   
`IOReturn IOUserClient::exportObjectToClient(task_t task, OSObject *obj, io_object_t *clientObj)`

`{`
    `mach_port_name_t name;    
    name = IOMachPort::makeSendRightForTask( task, obj, IKOT_IOKIT_OBJECT );`
    `*(mach_port_name_t *)clientObj = name; // (1). force the type convert to mach_port_name_t` 
    `if (obj) obj->release();`
    `return kIOReturnSuccess;`
`}`

We know io_object_t length is 8 bytes  and at (1) which  was  force convert to mach_port_name_t(4 bytes) ,so lead to  the high 4 bytes not inital
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →