KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting Mitigations
Tingting Yin, Zicong Gao, Zhenghang Xiao, Zheyu Ma, Min Zheng, Chao Zhang
摘要
macOS drivers, i.e., Kernel EXTensions (kext), are attractive attack targets for adversaries. However, automatically discovering vulnerabilities in kexts is extremely challenging because kexts are mostly closed-source, and the latest macOS running on customized Apple Silicon has limited tool-chain support. Most existing static analysis and dynamic testing solutions cannot be applied to the latest macOS. In this paper, we present the first smart fuzzing solution KextFuzz to detect bugs in the latest macOS kexts running on Apple Silicon. Unlike existing driver fuzzing solutions, KextFuzz does not require source code, execution traces, hypervisors, or hardware features (e.g., coverage tracing) and thus is universal and practical. We note that macOS has deployed many mitigations, including pointer authentication, code signature, and userspace kernel layer wrappers, to thwart potential attacks. These mitigations can provide extra knowledge and resources for us to enable kernel fuzzing. KextFuzz exploits these mitigation schemes to instrument the binary for coverage tracking, test privileged kext code that is guarded and infrequently accessed, and infer the type and semantic information of the kext interfaces. KextFuzz has found 48 unique kernel bugs in the macOS kexts and got five CVEs. Some bugs could cause severe consequences like non-recoverable denial-of-service or damages.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconHyerean Jang, Taehun Kim, Youngjoo ShinCCS 2024 · 被引用 6 次
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 被引用 1 次
- iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple SiliconKaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu 等CCS 2026
- Moneta: Ex-Vivo GPU Driver Fuzzing by Recalling In-Vivo Execution StatesJoonkyo Jung, Jisoo Jang, Yongwan Jo, Jonas Vinck 等NDSS 2025
- Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual DevicesZheyu Ma, Qiang Liu, Zheming Li, Tingting Yin 等NDSS 2025
它引用的顶会 Paper21
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili 等CCS 2017 · 被引用 195 次
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 被引用 187 次
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 被引用 180 次
相关 Paper
- SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS DriversWeiteng Chen, Yu Wang, Zheng Zhang, Zhiyun QianCCS 2021 · 被引用 25 次
- USBFuzz: A Framework for Fuzzing USB Drivers by Device EmulationHui Peng, Mathias PayerUSENIX Security 2020
- APICraft: Fuzz Driver Generation for Closed-source SDK LibrariesCen Zhang, Xingwei Lin, Yuekang Li, Yinxing Xue 等USENIX Security 2021 · 被引用 64 次
- UEFI Firmware Fuzzing with Simics Virtual PlatformZhenkun Yang, Yuriy Viktorov, Jin Yang, Jiewen Yao 等DAC 2020 · 被引用 8 次
- From Binary to Bug: Generation-Based Fuzzing for macOS MIG Services via Constraint RecoveryYi Fan, Ming Yuan, Haoyi Liu, Ximo Li 等CCS 2026
