May 8, 2015 Laurel, MD
Ian Beer, Google Project Zero: "A deep-dive into the many flavors of IPC available on OS X."
An overview of most IPC mechanisms on iOS/OS X. A quick look at Mach Message fundamentals is followed by a deep-dive into XPC services and the exploitation bugs therein. Beer describes privilege escalation models and unsafe versions of the XPC Services API. He concludes with a call for stronger security and for more effective sandboxing. Presented at the Jailbreak Security Summit, May 8, 2015, Laurel, Maryland, USA.