Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS
Luke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu, William Enck
Abstract
Apple uses several access control mechanisms to prevent third party applications from directly accessing security sensitive resources, including sandboxing and file access control. However, third party applications may also indirectly access these resources using inter-process communication (IPC) with system daemons. If these daemons fail to properly enforce access control on IPC, confused deputy vulnerabilities may result. Identifying such vulnerabilities begins with an enumeration of all IPC services accessible to third party applications. However, the IPC interfaces and their corresponding access control policies are unknown and must be reverse engineered at a large scale. In this paper, we present the Kobold framework to study NSXPC-based system services using a combination of static and dynamic analysis. Using Kobold, we discovered multiple NSXPC services with confused deputy vulnerabilities and daemon crashes. Our findings include the ability to activate the microphone, disable access to all websites, and leak private data stored in iOS File Providers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 12ed81d7-c7fb-4512-a9bf-80dc790d23a3Cited by top-tier papers2
- Bringing Balance to the Force: Dynamic Analysis of the Android Application FrameworkAbdallah Dawoud, Sven BugielNDSS 2021
- iOS, Your OS, Everybody's OS: Vetting and Analyzing Network Services of iOS ApplicationsZhushou Tang, Ke Tang, Minhui Xue, Yuan Tian et al.USENIX Security 2020
Builds on8
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- IMF: Inferred Model-based FuzzerHyungSeok Han, Sang Kil ChaCCS 2017 · 139 citations
- Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOSKai Chen, Xueqiang Wang, Yi Chen, Peng Wang et al.S&P 2016 · 111 citations
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang et al.NDSS 2018 · 95 citations
Related papers
- Chekhov's Gun: Uncovering Hidden Risks in macOS Application-Sandboxed PID-Domain ServicesMinghao Lin, Jiaxun Zhu, Tingting Yin, Zechao Cai et al.CCS 2025
- FReD: Identifying File Re-Delegation in Android System ServicesSigmund Albert Gorski III, Seaver Thorn, William Enck, Haining ChenUSENIX Security 2022
- SandScout: Automatic Detection of Flaws in iOS Sandbox ProfilesLuke Deshotels, Razvan Deaconescu, Mihai Chiroiu, Lucas Davi et al.CCS 2016 · 20 citations
- Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical RisksRishav Chourasia, Ergute Bao, Uzair Javaid, Xiaokui XiaoS&P 2026 · 2 citations
- Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the ComputerThanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan et al.USENIX Security 2018 · 25 citations
