Chekhov's Gun: Uncovering Hidden Risks in macOS Application-Sandboxed PID-Domain Services
Minghao Lin, Jiaxun Zhu, Tingting Yin, Zechao Cai, Guanxing Wen, Yanan Guo, Mengyuan Li
2025年份
摘要
macOS delegates many high-privilege operations to dedicated PID-domain services, which applications can register and communicate with through inter-process communication (IPC). This architecture improves userland stability and security but also introduces attractive attack surfaces for adversaries. In this paper, we systematically analyze PID-domain services and uncover an overlooked attack vector: PID-domain services that are restricted to an Application Sandbox identical to the calling application can still be exploited due to subtle entitlement differences.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOSLuke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu 等S&P 2020 · 被引用 10 次
- Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the ComputerThanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan 等USENIX Security 2018 · 被引用 25 次
- File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification System on Linux, Windows, and macOSSudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner 等CCS 2026
- Peep With A Mirror: Breaking The Integrity of Android App Sandboxing via Unprivileged Cache Side ChannelYan Lin, Joshua Wong, Xiang Li, Haoyu Ma 等USENIX Security 2024 · 被引用 2 次
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian 等CCS 2016 · 被引用 41 次
