Security

Alfie CG publishes write-up on Trigon, a deterministic kernel exploit based on CVE-2023-32434 that can’t fail

Matrix code hacked iPhone.

Another week, another intriguing write-up by the young and talented hobbyist security researcher @alfiecg_dev, who just this weekend published a blog post about a new deterministic kernel exploit called Trigon that is based on CVE-2023-32434, the same bug that the Kernel File Descriptor (KFD) exploit utilized with puaf_smith and was patched in iOS & iPadOS 16.5.1.

Security researcher wh1te4ever shares Safari-based remote execution exploit patched in iOS 16.5.1, macOS 13.4.1

MacBook Pro Matrix Hack banner image.

In case you weren’t already aware, there was a Safari-based remote code execution (RCE) bug in the wild that Apple patched in a rapid security update for iOS & iPadOS 16.5.1 dubbed CVE-2023-37450, and ENKI WhiteHat is credited with the original proof of concept (PoC) showcasing the bug. But what if we told you someone made an exploit out of it? Interestingly enough, that seems to be exactly what has happened.