bellis1000 Profile Banner
Billy Ellis Profile
Billy Ellis

@bellis1000

Followers
22K
Following
21K
Media
3K
Statuses
29K

iOS security researcher

London, England
Joined November 2013
Don't wanna be here? Send us removal request.
@bellis1000
Billy Ellis
7 months
Part 2 of Exploiting the iOS Kernel with PhysPuppet https://t.co/U7Al7Wl5EL
Tweet media one
5
37
235
@b1n4r1b01
binaryboy
26 days
Brief info and POC for this week's Apple 0click iOS 18.6.1 RCE bug CVE-2025-43300 https://t.co/EL3qg56N8X
Tweet media one
16
217
788
@alfiecg_dev
Alfie
2 months
Just released a short writeup for the A9 version of the Trigon exploit, which involves getting code execution on a coprocessor before exploiting the kernel - enjoy!
alfiecg.uk
Where did we leave off? Background: KTRR IORVBAR Coprocessors Always-On Processor Investigation AXI? What’s that?! Mapping DRAM Code execution Improving the strategy What about A7 and A8(X)? Conclu...
4
36
175
@bellis1000
Billy Ellis
2 months
Yeah didn’t take long
@app_settings
System Settings
2 months
the difference between beta 1 and beta 3 is CRAZY
Tweet media one
0
0
8
@bellis1000
Billy Ellis
3 months
Hiked up a volcano this past weekend. Mad views. 🌋
Tweet media one
2
0
32
@dillon_franke
Dillon Franke
3 months
I lightly mentioned CVE-2025-31235, a double-free I found in coreaudiod/CoreAudio, during my OffensiveCon presentation last month. It's been derestricted now, so enjoy my writeup which includes a PoC and dtrace script to help understand the vulnerability!
3
43
200
@bellis1000
Billy Ellis
3 months
Out-of-bounds swap on iOS heap when decoding a malicious audio stream (CVE-2025-31200) https://t.co/qRzR5Qo00T
1
34
194
@bellis1000
Billy Ellis
3 months
How This Weird Exploit Primitive Corrupts iOS Heap Memory
1
39
156
@bellis1000
Billy Ellis
3 months
I think this is the same effect as ‘learn by teaching’ when writing blogs. Fills the gaps in your knowledge.
0
0
6
@bellis1000
Billy Ellis
3 months
When facing a technical challenge, draft a message to a colleague/developer friend. I find that ~50% of the time I figure out the solution before clicking send, just by defining the issue clearly.
2
9
57
@bellis1000
Billy Ellis
3 months
The promo videos for Liquid Glass look beautiful, but seems implementation doesn’t land quite as well. I reckon Apple will partially revert this before full release, making elements more opaque again.
1
0
13
@ProjectZeroBugs
Project Zero Bugs
4 months
Samsung S24: Out of bounds write in VC1 Decoder (svc1d_rr_frm)
0
5
25
@bellis1000
Billy Ellis
4 months
Great research from Noah on the CoreAudio ITW vulnerability (CVE-2025-31200) patched in iOS 18.4.1 🐛
@noahhw4646
noah
4 months
My writeup on CVE-2025-31200. This ones an interesting one https://t.co/z2AmzC8A4W. thanks to @bellis1000 for the shoutout.
0
2
43
@ZygoSec
ZygoSec
4 months
This Video Can Exploit Your iPhone (CVE-2025-31200) https://t.co/cLxYQtdldg
Tweet media one
0
4
26
@bellis1000
Billy Ellis
4 months
Thanks to @HexRaysSA for sponsoring this video. You can use discount code BILLY50 to get 50% off your next IDA Pro individual license purchase. Contact sales@hex-rays.com
0
4
7
@bellis1000
Billy Ellis
4 months
This Video Can Exploit Your iPhone (CVE-2025-31200) https://t.co/sz8Skjxl9c
Tweet media one
2
110
552
@bellis1000
Billy Ellis
4 months
host_page_size()
Tweet media one
0
0
20
@bellis1000
Billy Ellis
5 months
CVE-2034-5678 in “CCTV firmware” from latest Black Mirror season. Bookmark this for 9 years from now and report your camera firmware bugs. You could align the show with reality
Tweet media one
4
0
28
@i41nbeer
Ian Beer
6 months
My writeup of the 2023 NSO in-the-wild iOS zero-click BLASTDOOR webp exploit: Blasting Past Webp - https://t.co/H4m8MBwoWN
21
234
706
@bellis1000
Billy Ellis
7 months
Great writeup, good job @alfiecg_dev
@alfiecg_dev
Alfie
7 months
I've just published a new blog post detailing how I developed a deterministic kernel exploit for iOS. Enjoy! https://t.co/ah8qtW0CG5
1
5
39