BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Breaking Hardware CFI with Sigreturn\n   Tags: DEF C
 ON Official Talk | Demo 💻\n   When: Friday\, Aug 7\, 17:30 - 17:59 PDT\
 n   Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - [1]Map\n\
 n   Description:\n\n   Modern ARM64 systems rely on hardware Control-Flow 
 Integrity (CFI)\n   such as PAC and BTI to kill classic ROP/JOP exploits. 
 Indirect\n   branches must land on valid targets\, returns are signed\, an
 d arbitrary\n   jumps are supposed to be over.\n\n   Except… it isn’t.
 \n\n   In this talk\, we show that\, by design\, there is a fundamental ga
 p\n   between POSIX signal handling and hardware CFI. Sigreturn acts as a\
 n   built-in\, kernel-assisted CFI bypass primitive\, enabling arbitrary\n
    control-flow transfers via crafted signal frames while bypassing CFI\n 
   enforcement.\n\n   We then explore what makes this work in practice on m
 odern Linux and\n   Android systems (including latest Ubuntu and Pixel dev
 ices): using\n   sigreturn as a practical exploitation primitive\, then pi
 voting with\n   ""cfi-safe stack pivots""\, abusing missing BTI enforcemen
 t on the\n   vDSO\, and leveraging GCC’s common default settings.\n\n   
 I'll present a PoC showing how these primitives can be chained in\n   clas
 sic SROP style\, and demonstrate how you can extend COOP/CFOP\n   beyond f
 unction-level control to achieve reliable arbitrary code\n   execution\, e
 ffectively breaking CFI again and again.\n\n   References\n\n     * \n\n  
      SROP\n\n         * "Framing Signals—A Return to Portable Shellcode"
 \, Erik\n           Bosman & Herbert Bos\, IEEE S&P 2014. Link:\n         
   https://www.cs.vu.nl/~herbertb/papers/srop_sp14.pdf\n\n     * \n\n      
  COOP\n\n         * "Counterfeit Object-oriented Programming"\, Schuster e
 t al.\,\n           IEEE S&P 2015. Link:\n           https://www.ieee-secu
 rity.org/TC/SP2015/papers-archived/6949a745.pdf\n\n     * \n\n       CFOP\
 n\n         * "Await() a Second: Evading Control Flow Integrity by Hijacki
 ng\n           C++ Coroutines"\, Marcos Bajo and Christian Rossow\, CISPA\
 n           Helmholtz Center for Information Security\, Usenix 2024. Link:
 \n           https://www.usenix.org/conference/usenixsecurity25/presentati
 on/bajo\n\n   SpeakerBio:  Omri "beta_b0t" Ben Bassat\, Tel Aviv Universit
 y\n\n   Omri Ben-Bassat is a vulnerability researcher with over a decade o
 f\n   experience in reverse engineering\, vulnerability finding\, binary\n
    exploitation\, and low-level vulnerability analysis\, specializing in\n
    IoT and embedded systems. He has presented his work at leading\n   secu
 rity conferences\, including Black Hat USA\, Black Hat Asia\, and RSA\n   
 Conference\, and has delivered awesome hands-on trainings at Black Hat\n  
  Asia and TyphoonCon. Omri is currently pursuing a master's degree at\n   
 Tel Aviv University\, where his research focuses on applying formal\n   me
 thods to software exploitation.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T005900Z
DTSTART:20260808T003000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:Breaking Hardware CFI with Sigreturn
END:VEVENT
END:VCALENDAR
