iDEA: Static Analysis on the Security of Apple Kernel Drivers
Xiaolong Bai, Luyi Xing, Min Zheng, Fuping Qu
Abstract
Drivers on Apple OSes (e.g., iOS, tvOS, iPadOS, macOS, etc.) run in the kernel space and driver vulnerabilities can incur serious security consequences. A recent report from Google Project Zero shows that driver vulnerabilities on Apple OSes have been actively exploited in the wild. Also, we observed that driver vulnerabilities have accounted for one-third of kernel bugs in recent iOS versions based on Apple's security updates. Despite the serious security implications, systematic static analysis on Apple drivers for finding security vulnerabilities has never been done before, not to mention any large-scale study of Apple drivers. In this paper, we developed the first automatic, static analysis tool iDEA for finding bugs in Apple driver binaries, which is applicable to major Apple OSes (iOS, macOS, tvOS, iPadOS). We summarized and tackled a set of Apple-unique challenges: for example, we show that prior C++ binary analysis techniques are ineffective (i.e., failing to recover C++ classes and resolve indirect calls) on Apple platform due to Apple's unique programming model. To solve the challenges, we found a reliable information source from Apple's driver programming and management model to recover classes, and identified the unique paradigms through which Apple drivers interact with user-space programs. iDEA supports customized, pluggable security policy checkers for its security analysis. Enabled by iDEA, we performed the first large-scale study of 3,400 Apple driver binaries across major Apple OSes and 15 OS versions with respect to two common types of security risks - race condition and out-of-bound read/write, and discovered 35 zero-day bugs. We developed PoC and end-to-end attacks to demonstrate the practical impacts of our findings. A portion of the bugs have been patched by recent Apple security updates or are scheduled to be fixed; others are going through Apple's internal investigation procedure. Our evaluation showed that iDEA incurs a low false-positive rate and time overhead.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 32db10a2-5f93-42a2-be28-fd4210e98ce0Cited by top-tier papers9
- SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS DriversWeiteng Chen, Yu Wang, Zheng Zhang, Zhiyun QianCCS 2021 · 25 citations
- Statically Discovering High-Order Taint Style Vulnerabilities in OS KernelsHang Zhang, Weiteng Chen, Yu Hao, Guoren Li et al.CCS 2021 · 23 citations
- SyzGen++: Dependency Inference for Augmenting Kernel Driver FuzzingWeiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou et al.S&P 2024 · 12 citations
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie et al.USENIX Security 2024 · 6 citations
- KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting MitigationsTingting Yin, Zicong Gao, Zhenghang Xiao, Zheyu Ma et al.USENIX Security 2023
Related papers
- DR. CHECKER: A Soundy Analysis for Linux Kernel DriversAravind Machiry, Chad Spensky, Jake Corina, Nick Stephens et al.USENIX Security 2017 · 126 citations
- POP and PUSH: Demystifying and Defending against (Mach) Port-oriented ProgrammingMin Zheng, Xiaolong Bai, Yajin Zhou, Chao Zhang et al.NDSS 2021
- APICraft: Fuzz Driver Generation for Closed-source SDK LibrariesCen Zhang, Xingwei Lin, Yuekang Li, Yinxing Xue et al.USENIX Security 2021 · 64 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel VulnerabilitiesLukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García et al.USENIX Security 2025
