41554 blogs · [ { "id": "01a0877c-a1e8-7029-8c81-5ee7f63db965", "title": "XProtectRemediatorDubRobber infoleak on macOS (CVE-2024-40842)", "url": "https://gergelykalman.com/CVE-2024-40842-xprotectremediatordubrobber-infoleak-on-macos.html", "published_at": "2026-07-10T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f6fd640c", "title": "State of the Apple Security Bounty program", "url": "https://gergelykalman.com/state-of-the-apple-security-bounty-program.html", "published_at": "2026-07-09T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f7f3373d", "title": "Corrections regarding rename()", "url": "https://gergelykalman.com/corrections-regarding-rename.html", "published_at": "2025-03-23T23:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f81efef0", "title": "badmalloc (CVE-2023-32428) - a macOS LPE", "url": "https://gergelykalman.com/badmalloc-CVE-2023-32428-a-macos-lpe.html", "published_at": "2024-11-23T23:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f8228b34", "title": "Tool release: fs_usage_ng", "url": "https://gergelykalman.com/tool-release-fs_usage_ng.html", "published_at": "2024-10-01T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f85ad07f", "title": "The forgotten art of filesystem magic - Alligatorcon 2024 slides", "url": "https://gergelykalman.com/the-forgotten-art-of-filesystem-magic-alligatorcon-2024-slides.html", "published_at": "2024-09-11T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f86d1b9f", "title": "The missing guide to the security of filesystems and file APIs (v1)", "url": "https://gergelykalman.com/the-missing-guide-to-the-security-of-filesystems-and-file-apis.html", "published_at": "2024-08-19T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f9652527", "title": "Why you shouldn't use a commercial VPN: Amateur hour with Windscribe", "url": "https://gergelykalman.com/why-you-shouldnt-use-a-commercial-vpn-amateur-hour-with-windscribe.html", "published_at": "2024-04-11T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f997b581", "title": "Hacking ISP CPE equipment: FiberHome", "url": "https://gergelykalman.com/hacking-isp-cpe-equipment-fiberhome.html", "published_at": "2023-12-17T23:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f9c3d625", "title": "You can watch my OBTSv6 talk on youtube", "url": "https://gergelykalman.com/my-obts-v6-talk-on-youtube.html", "published_at": "2023-12-17T23:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f9ee7a05", "title": "sqlol (CVE-2023-32422) - a macOS TCC bypass", "url": "https://gergelykalman.com/sqlol-CVE-2023-32422-a-macos-tcc-bypass.html", "published_at": "2023-11-14T23:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7f9fffa8b", "title": "lateralus (CVE-2023-32407) - a macOS TCC bypass", "url": "https://gergelykalman.com/lateralus-CVE-2023-32407-a-macos-tcc-bypass.html", "published_at": "2023-11-13T23:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7fa90f667", "title": "batsignal (no CVE) - a macOS LPE", "url": "https://gergelykalman.com/no-CVE-batsignal-a-macos-lpe.html", "published_at": "2023-10-29T23:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7fb84787e", "title": "Unexpected, Unreasonable, Unfixable - My slides from OBTS v6", "url": "https://gergelykalman.com/unexpected-unreasonable-unfixable-my-slides-from-obts-v6.html", "published_at": "2023-10-14T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7fc79d756", "title": "librarian (CVE-2023-38571) - a macOS TCC bypass in Music and TV", "url": "https://gergelykalman.com/CVE-2023-38571-a-macOS-TCC-bypass-in-Music-and-TV.html", "published_at": "2023-09-26T22:00:00+00:00" }, { "id": "01a0877c-a1e8-7029-8c81-5ee7fd34737f", "title": "unnamed sandbox escape (CVE-2023-32364) - a macOS sandbox escape by mounting", "url": "https://gergelykalman.com/CVE-2023-32364-a-macOS-sandbox-escape-by-mounting.html", "published_at": "2023-09-25T22:00:00+00:00" } ] posts Claim your blog
Back to gergelykalman.com
Blog · corpus.blog/blogs/gergelykalman.com/posts

gergelykalman.com

gergelykalman.com

2026

2025

2024

2023