Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning @BlackHatOfficialYT
Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning  @BlackHatOfficialYT
Uploaded August 2026 | Updated September 2026, 3 weeks ago
For years, macOS researchers have focused on high-privilege system and user domain services—yet a vast class of background daemons has quietly operated beneath the radar: PID-domain services. These processes, often reachable even from sandboxed apps, expose privileged functionality and sensitive system controls. Despite their enormous attack surface, they've remained largely unexplored and unprotected—until now.

In this Briefing, we will unveil the first large-scale automated framework for discovering logic vulnerabilities in PID-domain services, powered by LLM-assisted static analysis. We will start by dissecting historical flaws and Apple's patching patterns to formalize a repeatable attack model. Building on that foundation, our framework automatically enumerates connectable PID-domain daemons, decompiles their exported APIs, and leverages LLM semantic reasoning to classify sensitive operations across five categories—from file and privacy access to interprocess privilege crossing. We then map entitlements to these operations and apply taint analysis to trace attacker-controlled data into privileged sinks—surfacing hidden logic flaws that manual auditing would almost certainly miss.

Our evaluation uncovered 12 previously unknown vulnerabilities, including multiple sandbox escapes and TCC privacy bypasses—six of which have already been assigned CVEs by Apple. This research exposes a massive, underestimated attack surface within macOS's userspace and demonstrates how LLMs can be weaponized for scalable vulnerability discovery in closed-source ecosystems. Attendees will gain new insights into Apple's userspace attack surface, automated bug-hunting methodologies, and the next frontier of human–AI collaboration in exploit development.

l_m_h l_m_h | Independent Security Researcher
Yinyi Wu | Security Researcher, Dawn Security Lab, JD.com
Yingqi Shi | Security Researcher, DBAPPSecurity
Yuchong Xie | Security Researcher, The Hong Kong University of Science and Technology
Cheng Li | Security Researcher
Yizhuo Wang | Security Researcher

blackhat.com/asia-26/briefings/schedule/?#ai-in-the-loop-large-scale-macos-pid-domain-vulnerability-discovery-with-llm-reasoning-on-demand-only-50233
Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM ReasoningBlack Hat USA 2025 | Burning, Trashing, Spacecraft CrashingBlack Hat USA 2026 | Keynote: The End of Rare Defending When Offense Is CheapBlack Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)Black Hat Asia 2026 | Beyond the Golden Image: A Self-Healing Image Supply ChainBlack Hat Asia 2026 | IDEsaster 2.0: Another Novel Vulnerability Class in AI IDEsOperation PoisonedApple: Tracing Credit Card Information Theft to Payment FraudBlack Hat Vault | Cyber GrannyInternal Server Error: Exploiting Inter-Process Communication in SAPs HTTP ServerSecTor 2025 | Threat Architecture, Attack Surfaces & Real-World RiskSecTor 2025 | Unmasking a North Korean IT FarmBlack Hat Asia 2026 | Remote Server, Local Root. Welcome to MCP.
Black Hat |

Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER