BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Process injection: breaking all macOS security layer
 s with a\n   single vulnerability\n   When: Friday\, Aug 12\, 14:00 - 14:4
 5 PDT\n   Where: Caesars Forum - Academy 401-410\, 421 (Track 3) - [1]Map\
 n\n   SpeakerBio:Thijs Alkemade \, Security Researcher at Computest\n   Th
 ijs Alkemade (@xnyhps) works at the security research division of at\n   C
 omputest. This division is responsible for advanced security research\n   
 on commonly used systems and environments. Thijs has won Pwn2Own\n   twice
 \, by demonstrating a zero-day attack against Zoom at Pwn2Own\n   Vancouve
 r 2021 and by demonstrating multiple exploits in ICS systems\n   at Pwn2Ow
 n Miami 2022. In previous research he demonstrated several\n   attacks aga
 inst the macOS and iOS operating systems. He has a\n   background in both 
 mathematics and computer science\, which gives him a\n   lot of experience
  with cryptography and programming language theory.\n   Twitter: [2]@xnyhp
 s\n\n   Description:\n   macOS local security is shifting more and more to
  the iOS model\, where\n   every application is codesigned\, sandboxed and
  needs to ask for\n   permission to access sensitive data. New security la
 yers have been\n   added to make it harder for malware that has gained a f
 oothold to\n   compromise the user's most sensitive data. Changing the sec
 urity model\n   of something as large and established as macOS is a long p
 rocess\, as\n   it requires many existing parts of the system to be re-exa
 mined. For\n   example\, creating a security boundary between applications
  running as\n   the same user is a large change from the previous security
  model.\n\n   CVE-2021-30873 is a process injection vulnerability we repor
 ted to\n   Apple that affected all macOS applications. This was addressed 
 in the\n   macOS Monterey update\, but completely fixing this vulnerabilit
 y\n   requires changes to all third-party applications as well. Apple has\
 n   even changed the template for new applications in Xcode to assist\n   
 developers with this.\n\n   In this talk\, we'll explain what a process in
 jection vulnerability is\n   and why it can have critical impact on macOS.
  Then\, we'll explain the\n   details of this vulnerability\, including ho
 w to exploit insecure\n   deserialization in macOS. Finally\, we will expl
 ain how we exploited it\n   to escape the macOS sandbox\, elevate our priv
 ileges to root and bypass\n   SIP.\n\n   '\n\n   1. https://defcon.outel.o
 rg/consolidated_page.html#CaesarsAcademyBR\n   2. https://twitter.com/xnyh
 ps\n\n\n
DTEND:20220812T214500Z
DTSTART:20220812T210000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:Process injection: breaking all macOS security layers with a single
  vulnerability
END:VEVENT
END:VCALENDAR
