SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple Silicon
Hyerean Jang, Taehun Kim, Youngjoo Shin
摘要
Apple silicon is the proprietary ARM-based processor that powers the mainstream of Apple devices. The move to this proprietary architecture presents unique challenges in addressing security issues, requiring huge research efforts into the security of Apple silicon-based systems. In this paper, we study the security of KASLR, the randomization-based kernel hardening technique, on the state-of-the-art macOS system equipped with Apple silicon processors. Because KASLR has been subject to many microarchitectural side-channel attacks, the latest operating systems, including macOS, use kernel isolation, which separates the kernel page table from the userspace table. Kernel isolation in macOS provides a barrier to KASLR break attacks. To overcome this, we exploit speculative execution in system calls. By using Spectre-type gadgets in system calls, an unprivileged attacker can cause translations of the attacker's chosen kernel addresses, causing the TLB to change according to the validity of the address. This allows the construction of an attack primitive that breaks KASLR bypassing kernel isolation. Since the TLB is used as a side-channel source, we reverse-engineer the hidden internals of the TLB on various M-series processors using a hardware performance monitoring unit. Based on our attack primitive, we implement SysBumps, the first KASLR break attack on macOS for Apple silicon. Throughout evaluation, we show that SysBumps can effectively break KASLR across different M-series processors and macOS versions. We also discuss possible mitigations against the proposed attack.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Towards Practical Interrupt Side-Channel Attacks on macOS for Apple SiliconXin Zhang, Chang Liu, Jiajun Zou, Yi Yang 等ISCA 2026 · 被引用 1 次
- SSBench: Automated Characterization of Memory Dependence Predictors on Modern CPUsChang Liu, Yu Jin, Yuchen Fan, Tianrui Xiao 等ISCA 2026 · 被引用 1 次
- Exploiting TLBs in Virtualized GPUs for Cross-VM Side-Channel AttacksHongyue Jin, Yanan Guo, Zhenkai ZhangNDSS 2026
- iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple SiliconKaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu 等CCS 2026
它引用的顶会 Paper30
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 被引用 357 次
相关 Paper
- AMD Prefetch Attacks through Power and TimeMoritz Lipp, Daniel Gruss, Michael SchwarzUSENIX Security 2022
- iLeakage: Browser-based Timerless Speculative Execution Attacks on Apple DevicesJason Kim, Stephan van Schaik, Daniel Genkin, Yuval YaromCCS 2023 · 被引用 16 次
- SLAP: Data Speculation Attacks via Load Address Prediction on Apple SiliconJason Kim, Daniel Genkin, Yuval YaromS&P 2025
- Fractal: An Operating System Designed for Microarchitecture Reverse EngineeringJoseph Ravichandran, Mengjia YanS&P 2026
- PACMAN: attacking ARM pointer authentication with speculative executionJoseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia YanISCA 2022 · 被引用 68 次
