56,966 blogs · [ { "id": "01a08761-7582-7033-92a7-94b17f4796dc", "title": "Inside iOS 27's Reworked Stub Islands", "url": "https://codecolor.ist/posts/2026-06-15-ios27-reworked-stub-islands/", "published_at": "2026-06-15T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b17ff2ae03", "title": "Abusing tclsh to Load (Remote) Shellcode on macOS", "url": "https://codecolor.ist/posts/2025-10-31-macos-abuse-tcl-lol/", "published_at": "2025-10-31T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b180bbeccc", "title": "Mistuned Part 3: PAC Bypass", "url": "https://codecolor.ist/posts/2021-09-10-mistuned-part-iii/", "published_at": "2021-09-10T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b181a509bb", "title": "Mistuned Part 2: Butterfly Effect", "url": "https://codecolor.ist/posts/2021-08-05-mistuned-part-ii/", "published_at": "2021-08-05T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b181ac69b6", "title": "Mistuned Part 1: Client-side XSS to Calculator and More", "url": "https://codecolor.ist/posts/2021-08-04-mistuned-part-i/", "published_at": "2021-08-04T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b181e34d4d", "title": "Quick Analysis for the SSID Format String Bug", "url": "https://codecolor.ist/posts/2021-06-20-quick-analysis-wifid/", "published_at": "2021-06-20T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b182894ec1", "title": "See No Eval: Runtime Dynamic Code Execution in Objective-C", "url": "https://codecolor.ist/posts/2021-01-16-see-no-eval-runtime-code-execution-objc/", "published_at": "2021-01-16T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b183140916", "title": "X Site eScape (Part II): Look Up a Shell in the Dictionary", "url": "https://codecolor.ist/posts/2020-08-06-x-site-escape-part-ii-look-up-a-shell-in-the-dictionary/", "published_at": "2020-08-06T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b1840cbe53", "title": "X Site eScape (Part III): CVE-2020-9860, A Copycat", "url": "https://codecolor.ist/posts/2020-07-01-x-site-escape-part-iii-cve-2020-9860-a-copycat/", "published_at": "2020-07-01T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b1843ba361", "title": "X Site eScape (Part I): Exploitation of An Old CoreFoundation Sandbox Bug", "url": "https://codecolor.ist/posts/2020-05-28-x-site-escape-part-i-exploitation-of-and-old-corefoundation-sandbox-bug/", "published_at": "2020-05-28T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b184af2538", "title": "Revisiting An Old MediaRemote Bug (CVE-2018-4340)", "url": "https://codecolor.ist/posts/2020-05-27-revisiting-an-old-mediaremote-bug-cve-2018-4340/", "published_at": "2020-05-27T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b18529eb63", "title": "Two macOS Persistence Tricks Abusing Plugins", "url": "https://codecolor.ist/posts/2019-11-21-two-macos-persistence-tricks-abusing-plugins/", "published_at": "2019-11-21T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b185fb6781", "title": "Rootpipe Reborn (Part II): CVE-2019-8565 Feedback Assistant Race Condition", "url": "https://codecolor.ist/posts/2019-04-21-rootpipe-reborn-part-ii/", "published_at": "2019-04-21T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b186cddcf1", "title": "Rootpipe Reborn (Part I): TimeMachine Command Injection", "url": "https://codecolor.ist/posts/2019-04-13-rootpipe-reborn-part-i/", "published_at": "2019-04-13T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b1872fd8db", "title": "One-liner Safari Sandbox Escape Exploit", "url": "https://codecolor.ist/posts/2019-03-26-one-liner-safari-sandbox-escape-exploit/", "published_at": "2019-03-26T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b18757e3c1", "title": "CVE-2018-4991: Adobe Creative Cloud Desktop Local Privilege Escalation via Signature Bypass", "url": "https://codecolor.ist/posts/2018-08-22-cve-2018-4991-adobe-creative-cloud-desktop-local-privilege-escalation-via-signature-bypass/", "published_at": "2018-08-22T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b1878b936f", "title": "CVE-2018-8412: MS Office 2016 for Mac Privilege Escalation via a Legacy Package", "url": "https://codecolor.ist/posts/2018-08-22-cve-2018-8412-ms-office-2016-for-mac-privilege-escalation-via-a-legacy-package/", "published_at": "2018-08-22T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b1880921fe", "title": "Something About #realworldctf doc2own", "url": "https://codecolor.ist/posts/2018-08-07-something-about-realworldctf-doc2own/", "published_at": "2018-08-07T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b188a3c92c", "title": "Bypass macOS Rootless by Sandboxing", "url": "https://codecolor.ist/posts/2018-06-18-bypass-macos-rootless-by-sandboxing/", "published_at": "2018-06-18T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b188cb0110", "title": "Visual Studio Code silently Fixed a Remote Code Execution Vulnerability", "url": "https://codecolor.ist/posts/2018-03-16-visual-studio-code-silently-fixed-a-remote-code-execution-vulnerability/", "published_at": "2018-03-16T00:00:00+00:00" }, { "id": "01a08761-7582-7033-92a7-94b189c120d3", "title": "Bypass PHP Safe Mode by Abusing SQLite3's FTS Tokenizer", "url": "https://codecolor.ist/posts/2016-01-20-bypass-php-safe-mode-by-abusing-sqlite3-s-fts-tokenizer/", "published_at": "2016-01-20T00:00:00+00:00" } ] posts Claim your blog
Back to codecolor.ist
Blog · corpus.blog/blogs/codecolor.ist/posts

codecolor.ist

codecolor.ist

2026

2025

2021

2020

2019

2018

2016