Uploaded December 2019 | Updated September 2026, 2 weeks ago
Ned Williamson of Google Project Zero explains how he discovered SockPuppet (CVE-2019-8605), a use-after-free vulnerability in the XNU kernel used by iOS and macOS. We look at how the bug becomes reachable from the iOS app sandbox and what exploitation primitives it provides for a jailbreak.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-system-hacking/yt-os-security
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Google Project Zero Blog: googleprojectzero.blogspot.com/2019/12/sockpuppet-walkthrough-of-kernel.html
Ned on Twitter: twitter.com/NedWilliamson
Ned Williamson - Modern Source Fuzzing (OffensiveCon19): youtube.com/watch?v=xzG0pLM4Q64
CHAPTERS
00:00 - The SockPuppet jailbreak bug
01:17 - Finding SockPuppet with XNU network fuzzing
03:46 - Why Apple publishes the XNU kernel source
04:39 - From a root-only crash to an iOS sandbox bug
06:08 - The fuzzer's socket and syscall sequence
08:07 - Understanding the stale-pointer use-after-free
09:06 - Locating and explaining the missing NULL assignment
13:13 - Triggering the use-after-free with socket options
14:55 - Turning the dangling pointer into read and write
17:25 - Heap spray, arbitrary read, and arbitrary free
19:47 - Why the apparent arbitrary write fails
21:40 - Turning arbitrary free into targeted exploitation
22:37 - What the complete jailbreak still needs
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#iOSSecurity #KernelExploitation #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Ned Williamson of Google Project Zero explains how he discovered SockPuppet (CVE-2019-8605), a use-after-free vulnerability in the XNU kernel used by iOS and macOS. We look at how the bug becomes reachable from the iOS app sandbox and what exploitation primitives it provides for a jailbreak.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-system-hacking/yt-os-security
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Google Project Zero Blog: googleprojectzero.blogspot.com/2019/12/sockpuppet-walkthrough-of-kernel.html
Ned on Twitter: twitter.com/NedWilliamson
Ned Williamson - Modern Source Fuzzing (OffensiveCon19): youtube.com/watch?v=xzG0pLM4Q64
CHAPTERS
00:00 - The SockPuppet jailbreak bug
01:17 - Finding SockPuppet with XNU network fuzzing
03:46 - Why Apple publishes the XNU kernel source
04:39 - From a root-only crash to an iOS sandbox bug
06:08 - The fuzzer's socket and syscall sequence
08:07 - Understanding the stale-pointer use-after-free
09:06 - Locating and explaining the missing NULL assignment
13:13 - Triggering the use-after-free with socket options
14:55 - Turning the dangling pointer into read and write
17:25 - Heap spray, arbitrary read, and arbitrary free
19:47 - Why the apparent arbitrary write fails
21:40 - Turning arbitrary free into targeted exploitation
22:37 - What the complete jailbreak still needs
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#iOSSecurity #KernelExploitation #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.










