DEF CON 27 - Xiaolong Bai - HackPac Hacking Pointer Authentication in iOS User Space @HackersOnBoard
DEF CON 27 - Xiaolong Bai - HackPac Hacking Pointer Authentication in iOS User Space  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 1 hour ago
Pointer Authentication (in short, PAuth) is the latest security mechanism in iOS. It is proposed to protect the integrity of pointers with hardware-assisted encryption, thus eliminating the threats of code-reuse attacks. In PAuth, a cryptographic signature called PAC is calculated from a pointer value and inserted into the pointer. When the pointer is about to be used, the PAC is extracted and verified whether it is consistent with the original pointer value. In this way, PAuth is able to ensure that the pointers are not tampered. iOS deployed PAuth in user-space system services, protecting pointers that may affect the control flow and preventing code-reuse attacks like ROP and JOP.

However, in our study, we found that a fatal flaw in the implementation of iOS PAuth makes user-space system services till vulnerable to code-reuse attacks. The flaw is: iOS uses the same signing key in different user-space processes. This flaw allows a signed pointer from a malicious process can be correctly verified in a system service, thus making it possible to launch JOP. In this talk, we will explain how we found the flaw and why it is inevitable. In advance, we will demonstrate how to leverage this flaw and launch JOP attacks in a PAuth-protected system service. Also, we will propose a new tool, PAC-gadget, to automatically find JOP gadgets in PAuth-protected binaries.
DEF CON 27 - Xiaolong Bai - HackPac Hacking Pointer Authentication in iOS User SpaceDEF CON 27 - Itzik Kotler - Process Injection Techniques Gotta Catch Them AllBlack Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire HoleDEF CON 27 - Can You Track Me Now? Why The Phone Companies Are Such A Privacy DisasterBlack Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOMBlack Hat USA 2018 - Remotely Attacking System FirmwareBlack Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus EmulatorDEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the WebDEF CON 27 - The Dark Tangent - Closing CeremoniesOver-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla CarsBlack Hat USA 2018 - Outsmarting the Smart CityBlack Hat USA 2018 - Meltdown Basics, Details, Consequences
HackersOnBoard |

DEF CON 27 - Xiaolong Bai - HackPac Hacking Pointer Authentication in iOS User Space

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER