Meysam Profile
Meysam

@R00tkitSMM

Followers
9,449
Following
653
Media
18
Statuses
466
Explore trending content on Musk Viewer
@R00tkitSMM
Meysam
5 months
C’mon Apple, iOS kernel vulnerability is not eligible for bounty? What would then be? It could have been ended up in @DonnchaC or @jsrailton blogs. 🤦‍♂️
Tweet media one
@R00tkitSMM
Meysam
5 months
I reported CVE-2024-27804, an iOS/macOS kernel vulnerability that leads to the execution of arbitrary code with kernel privileges. Will publish the POC soon.
42
149
1K
91
184
2K
@R00tkitSMM
Meysam
5 months
I reported CVE-2024-27804, an iOS/macOS kernel vulnerability that leads to the execution of arbitrary code with kernel privileges. Will publish the POC soon.
42
149
1K
@R00tkitSMM
Meysam
4 months
I have new t-shirt.
Tweet media one
4
81
636
@R00tkitSMM
Meysam
5 months
POC for CVE-2024-27804 Wanted to share it after finishing a blogpost. but decided to share it.
@R00tkitSMM
Meysam
5 months
I reported CVE-2024-27804, an iOS/macOS kernel vulnerability that leads to the execution of arbitrary code with kernel privileges. Will publish the POC soon.
42
149
1K
30
141
534
@R00tkitSMM
Meysam
5 months
seem Apple have concluded that the reported CVE is not exploitable and they are planning to update the description to accurately describe the issue as an unexpected system termination rather than arbitrary code execution, but for good faith they will reward me 1000$.thanks @Apple
@R00tkitSMM
Meysam
5 months
C’mon Apple, iOS kernel vulnerability is not eligible for bounty? What would then be? It could have been ended up in @DonnchaC or @jsrailton blogs. 🤦‍♂️
Tweet media one
91
184
2K
26
16
295
@R00tkitSMM
Meysam
3 months
Tweet media one
0
17
273
@R00tkitSMM
Meysam
24 days
iPhone 16 Pro Max ✅ Hacking time.
Tweet media one
6
7
201
@R00tkitSMM
Meysam
4 months
I have received another CVE in iOS/macOS CVE-2024-27802 Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
5
22
168
@R00tkitSMM
Meysam
24 days
۱۲ تا CVE تو ۲۰۲۳ و ۲۰۲۴ تا الان از ایفون/مک. 📈
@R00tkitSMM
Meysam
24 days
iPhone 16 Pro Max ✅ Hacking time.
Tweet media one
6
7
201
12
4
147
@R00tkitSMM
Meysam
7 months
I added two more post to my three days old blog 1- "ImageIO, the infamous iOS Zero Click Attack Vector." 2- "CVE-2016-0040 Story of Uninitialized Pointer in Windows Kernel"
0
35
140
@R00tkitSMM
Meysam
4 months
bought a MacBook with the Apple bug bounty. :)
Tweet media one
8
3
126
@R00tkitSMM
Meysam
4 months
The new Google Project Zero blog shows how much effort is required to do research and how to build foundation and where to get started.
0
22
124
@R00tkitSMM
Meysam
1 month
See you in Korea/Seoul soon!
@POC_Crew
POC_Crew 👨‍👩‍👦‍👦
1 month
[POC2024] SPEAKER UPDATE 7⃣ 👤 @R00tkitSMM - "Pishi: Coverage-Guided Fuzzing of the XNU Kernel and Arbitrary KEXT" #POC2024
Tweet media one
0
7
66
11
10
122
@R00tkitSMM
Meysam
5 months
POC and blog
@R00tkitSMM
Meysam
5 months
use-after-free in linux kernel reported by me and @zer0legday is fixed here: fix: add missing locking around taking dentry fid list will publish the POC very soon.
3
12
99
0
26
123
@R00tkitSMM
Meysam
3 months
forget to say that I found CVE-2024-27802 in Apple's Metal.framework while was trying to find attack surface in WebGPU to escape to GPU process. after spending considerable time on Render<->GPU IPC, I found that some texture parsing happens in GPU.
4
16
120
@R00tkitSMM
Meysam
14 days
I used Ghidra in this project as a first experience, it worked very well even better than IDA Pro.
@POC_Crew
POC_Crew 👨‍👩‍👦‍👦
1 month
[POC2024] SPEAKER UPDATE 7⃣ 👤 @R00tkitSMM - "Pishi: Coverage-Guided Fuzzing of the XNU Kernel and Arbitrary KEXT" #POC2024
Tweet media one
0
7
66
4
7
116
@R00tkitSMM
Meysam
3 months
in Intel based macOS, Crowdstrike's falcon utilizes a KEXT which could potentially be vulnerable. however on Apple Silicon it employs System Extensions instead. thanks Apple for keeping kernel a forbidden place :)
8
10
102
@R00tkitSMM
Meysam
5 months
use-after-free in linux kernel reported by me and @zer0legday is fixed here: fix: add missing locking around taking dentry fid list will publish the POC very soon.
3
12
99
@R00tkitSMM
Meysam
3 months
writing externally optimized code is difficult I had deadly performance issue, after a lot of investigation the issue turned out to be: for bool condition; if(condition == true) // is a lot slower than if ( condition)
Tweet media one
11
6
98
@R00tkitSMM
Meysam
5 months
Tweet media one
@R00tkitSMM
Meysam
5 months
use-after-free in linux kernel reported by me and @zer0legday is fixed here: fix: add missing locking around taking dentry fid list will publish the POC very soon.
3
12
99
2
1
86
@R00tkitSMM
Meysam
4 months
a good paper, Control Flow Integrity on Arm64
0
20
86
@R00tkitSMM
Meysam
4 months
Analysing an image exploit sample is so major work, you have to see how it modifies states inside its own "weird machine". #WebP Ian Beer - Blasting Past Webp.
1
13
83
@R00tkitSMM
Meysam
4 months
I’m soo happy that my new macOS kernel fuzzer works like a charm. 🪄 🧙‍♀️🐈
2
0
71
@R00tkitSMM
Meysam
4 months
یه CVE دیگه از اپل 🍎 دریافت شد. 🔥
@R00tkitSMM
Meysam
4 months
I have received another CVE in iOS/macOS CVE-2024-27802 Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
5
22
168
2
3
71
@R00tkitSMM
Meysam
2 months
Paper day 1- EXPRACE: Exploiting Kernel Races through Raising Interrupts and 2- Racing against the clock -- hitting a tiny kernel race window ( this is really cool)
0
15
68
@R00tkitSMM
Meysam
4 months
Tweet media one
2
3
65
@R00tkitSMM
Meysam
5 months
Inspired by @ifsecure , to force h.264/h.265 decoding to be "inprocess", then I fuzzed both IOConnectCallMethod and h.264/h.265 input video together.
4
8
64
@R00tkitSMM
Meysam
4 months
I don’t do bug bounty for bounty, I do it because I love to understand how things work. And mostly at my free time.
5
3
65
@R00tkitSMM
Meysam
4 months
Damn it, there was a very ridiculous mistake in my blogpost "Structure-Aware linux kernel Fuzzing with libFuzzer" I had forgotten to stop/start KCOV, in case you are using it. 🤦‍♂️🤦‍♂️
0
8
64
@R00tkitSMM
Meysam
5 months
A linux kernel vulnerability I and @zer0legday found and reported to @thezdi .
Tweet media one
1
3
63
@R00tkitSMM
Meysam
4 months
macOS/iOS kernel research needs a real dev. couldn't find a way to load kext via parallels desktop even though it allows to disable SIP in last versions. and It is currently impossible to sign in with your Apple ID in a macOS Arm VM🤦‍♂️ and don't want to mess up my own macBook 👇
3
2
60
@R00tkitSMM
Meysam
11 days
fuzzing TIP: if you see "Image File Format" (in this case: AV1) inside a container format(in this case: HEIF/AVIF), try to fuzz the "Image File Format" directly too.
@ProjectZeroBugs
Project Zero Bugs
11 days
Effective Fuzzing: A Dav1d Case Study
0
14
49
0
1
69
@R00tkitSMM
Meysam
4 months
Most of my research happens at a cafe in Berlin, I should share my bounties with baristas.
1
1
61
@R00tkitSMM
Meysam
5 months
found via jackalope. cc @ifsecure
1
2
60
@R00tkitSMM
Meysam
5 months
@TimGMichaud @DonnchaC @jsrailton Appreciate your support, I have already sent them my comments.
0
0
58
@R00tkitSMM
Meysam
4 months
I can’t agree more with Mateusz Personal takeaways Long, persistent analysis pays off
Tweet media one
0
2
56
@R00tkitSMM
Meysam
3 months
PACMAN: Attacking ARM Pointer Authentication with Speculative Execution
1
10
52
@R00tkitSMM
Meysam
10 days
Understanding and Improving Coverage Tracking with AFL++
0
13
72
@R00tkitSMM
Meysam
3 months
Demystifying Pointer Authentication on Apple M1
0
7
50
@R00tkitSMM
Meysam
3 months
Going to finish some TODOs in my soon to be open source macOS kernel fuzzer.
1
1
47
@R00tkitSMM
Meysam
5 months
The difficult part of vulnerability research is sticking to one particular target :)
1
1
48
@R00tkitSMM
Meysam
3 months
If I document how much I have spent on failed steps to have a working idea, my blog would be a book. But we just document the last successful steps.
0
1
45
@R00tkitSMM
Meysam
4 months
CVE-2024-39463 assigned to our report.
@R00tkitSMM
Meysam
5 months
use-after-free in linux kernel reported by me and @zer0legday is fixed here: fix: add missing locking around taking dentry fid list will publish the POC very soon.
3
12
99
2
2
43
@R00tkitSMM
Meysam
3 months
LightEMU: Hardware Assisted Fuzzing of Trusted Applications
@R00tkitSMM
Meysam
3 months
CROWBAR: Natively Fuzzing Trusted Applications Using ARM CoreSight
2
3
49
1
7
44
@R00tkitSMM
Meysam
1 month
The first thing that I going to do is panicking the kernel. 😈
@R00tkitSMM
Meysam
1 month
Ok then, have to wait until Friday to preorder an iPhone 16.
2
0
16
1
1
43
@R00tkitSMM
Meysam
4 months
Good read
0
1
42