BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Keychained Melody - Grabbing the Keys to the iCloud 
 Kingdom\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   Whe
 n: Friday\, Aug 7\, 11:00 - 11:59 PDT\n   Where: LVCCW Level 1 Hall 3 906 
 (Main Track 3) and DCTV-3 - [1]Map\n\n   Description:\n\n   The Apple Keyc
 hain has become a cornerstone of credential management\n   for millions of
  users across the Apple ecosystem. In response\, Apple\n   has implemented
  robust protections for the iCloud Keychain —\n   restricting synchroniz
 ation exclusively to devices within Apple’s\n   “Circle of Trust” an
 d encrypting stored secrets with keys\n   protected by the Secure Enclave.
  These layered defenses are designed\n   to ensure that even physical acqu
 isition of Keychain data from\n   Apple’s servers yields nothing actiona
 ble.\n\n   This talk introduces a novel vulnerability (CVE-2026-28860) tha
 t\n   fundamentally undermines these protections. Leveraging a deep\n   un
 derstanding of macOS internals\, we demonstrate a technique capable\n   of
  extracting all passwords stored within the Keychain — requiring\n   nei
 ther root privileges\, a user password\, nor any prompts to the user.\n   
 Beyond credential theft\, we explore the broader attack surface this\n   v
 ulnerability exposes\, presenting additional scenarios where data\n   glea
 ned from the iCloud Keychain enables further\, more severe\n   compromise.
 \n\n   Speakers:Alex Radocea\,Jaron Bradley\n\n   SpeakerBio:  Alex Radoce
 a\n\n   Founder of Supernetworks and cofounder of Longterm Security. Alex\
 n   started in security pentesting financial firms on Wall Street at\n   M
 atasano and cofounded RPISEC at RPI. He has worked on Apple's Product\n   
 Security team\, engineering at CrowdStrike\, and Spotify's Security\n   te
 am. His research — presented at Black Hat and REcon — spans\n   mobile
  messenger cryptography\, kernel security\, binary static\n   analysis\, a
 nd browser hardening\, including the discovery of critical\n   flaws in Ap
 ple's iCloud Keychain.\n\n   SpeakerBio:  Jaron Bradley\, Jamf\n\n   Jaron
  is the Director of Jamf Threat Labs where he focuses on\n   discovering n
 ew ways to keep user's safe on Apple devices. He is\n   author of the book
 s "Threat Hunting macOS" and "OS X Incident\n   Response". In his free tim
 e he manages themittenmac.com\, a site\n   dedicated to helping others lea
 rn security on the Apple ecosystem.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n
 \n\n
DTEND:20260807T185900Z
DTSTART:20260807T180000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Keychained Melody - Grabbing the Keys to the iCloud Kingdom
END:VEVENT
END:VCALENDAR
