41554 blogs · [ { "id": "01a08c63-9dd6-71c5-816a-55220d7ca2ba", "title": "Crossing the Golden Gate: macOS's New Application Support Protection", "url": "https://wojciechregula.blog/post/golden-gate-appdata-protection/", "published_at": "2026-07-16T10:00:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55220deb8aab", "title": "TCC bypasses via launch services", "url": "https://wojciechregula.blog/post/tcc-bypasses-via-launch-services/", "published_at": "2024-10-20T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55220e29f692", "title": "Multiple TCC bypasses via SQLite environment variables", "url": "https://wojciechregula.blog/post/multiple-tcc-bypasses-via-sqlite-env-vars/", "published_at": "2024-06-24T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55220e962742", "title": "ELECTRONizing macOS privacy", "url": "https://wojciechregula.blog/post/electroniz3r/", "published_at": "2024-01-23T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55220f7b679a", "title": "macOS Atlassian Companion Remote Code Execution", "url": "https://wojciechregula.blog/post/macos-atlassian-companion-rce/", "published_at": "2023-07-09T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552210385b59", "title": "Bypass TCC via iCloud", "url": "https://wojciechregula.blog/post/bypass-tcc-via-icloud/", "published_at": "2023-03-04T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522112d2a3b", "title": "macOS Sandbox Escape vulnerability via Terminal", "url": "https://wojciechregula.blog/post/macos-sandbox-escape-via-terminal/", "published_at": "2022-11-18T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552211e2d215", "title": "macOS Red Teaming: Apple Dev-ID signed Java environment", "url": "https://wojciechregula.blog/post/macos-red-teaming-apple-signed-java/", "published_at": "2022-07-11T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522120ee2d3", "title": "macOS Red Teaming: Initial access via AppleScript URL", "url": "https://wojciechregula.blog/post/macos-red-teaming-initial-access-via-applescript-url/", "published_at": "2022-03-18T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522127cd89c", "title": "macOS Red Teaming: Bypass TCC with old apps", "url": "https://wojciechregula.blog/post/macos-red-teaming-bypass-tcc-with-old-apps/", "published_at": "2022-03-10T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552212b6214e", "title": "macOS Red Teaming: Get Active Directory credentials from NoMAD", "url": "https://wojciechregula.blog/post/macos-red-teaming-get-ad-credentials-from-nomad/", "published_at": "2022-03-03T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552213072a3d", "title": "Bypass TCC via privileged helpers aka CVE-2020-10008", "url": "https://wojciechregula.blog/post/bypass-tcc-via-privileged-helpers-aka-cve-2020-10008/", "published_at": "2021-12-07T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522131ab428", "title": "Change home directory and bypass TCC aka CVE-2020-27937", "url": "https://wojciechregula.blog/post/change-home-directory-and-bypass-tcc-aka-cve-2020-27937/", "published_at": "2021-09-09T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552213661855", "title": "Play the music and bypass TCC aka CVE-2020-29621", "url": "https://wojciechregula.blog/post/play-the-music-and-bypass-tcc-aka-cve-2020-29621/", "published_at": "2021-09-02T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552213f66cff", "title": "M1 Macs GateKeeper bypass aka CVE-2021-30658", "url": "https://wojciechregula.blog/post/m1-macs-gatekeeper-bypass-aka-cve-2021-30658/", "published_at": "2021-06-18T10:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552214cb9706", "title": "Press 5 keys and become r00t aka CVE-2021-30655", "url": "https://wojciechregula.blog/post/press-5-keys-and-become-root-aka-cve-2021-30655/", "published_at": "2021-05-10T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552214cd582c", "title": "How to rob a (Fire)fox", "url": "https://wojciechregula.blog/post/how-to-rob-a-firefox/", "published_at": "2021-03-09T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522151ff03d", "title": "When vulnerable library is actually your physical book", "url": "https://wojciechregula.blog/post/when-vulnerable-library-is-actually-your-physical-book/", "published_at": "2021-01-21T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552215f97f5c", "title": "Network Extension Framework aka Swiss cheese", "url": "https://wojciechregula.blog/post/network-extension-framework-aka-swiss-cheese/", "published_at": "2020-11-18T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522163ebf9c", "title": "Stealing macOS apps' Keychain entries", "url": "https://wojciechregula.blog/post/stealing-macos-apps-keychain-entries/", "published_at": "2020-10-30T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522166dfcf8", "title": "Learn XPC exploitation - Part 3: Code injections", "url": "https://wojciechregula.blog/post/learn-xpc-exploitation-part-3-code-injections/", "published_at": "2020-06-29T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522171880b8", "title": "Stealing your SMS messages with iOS 0day", "url": "https://wojciechregula.blog/post/stealing-your-sms-messages-with-ios-0day/", "published_at": "2020-04-30T00:00:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552217914e4a", "title": "Learn XPC exploitation - Part 2: Say no to the PID!", "url": "https://wojciechregula.blog/post/learn-xpc-exploitation-part-2-say-no-to-the-pid/", "published_at": "2020-04-23T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522184fa8a4", "title": "Learn XPC exploitation - Part 1: Broken cryptography", "url": "https://wojciechregula.blog/post/learn-xpc-exploitation-part-1-broken-cryptography/", "published_at": "2020-03-28T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-5522192e0855", "title": "Abusing Electron apps to bypass macOS' security controls", "url": "https://wojciechregula.blog/post/abusing-electron-apps-to-bypass-macos-security-controls/", "published_at": "2019-12-18T13:37:00+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-552219aebd04", "title": "Dangerous Get Task Allow Entitlement on iExplorer example", "url": "https://wojciechregula.blog/post/dangerous-get-task-allow-entitlement/", "published_at": "2019-08-08T18:13:01+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221a50411a", "title": "Stealing Bear Notes With Url Schemes", "url": "https://wojciechregula.blog/post/stealing-bear-notes-with-url-schemes/", "published_at": "2019-03-02T10:12:10+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221ad64ff9", "title": "Dissecting Logitech Options on macOS", "url": "https://wojciechregula.blog/post/dissecting-logitech-options-on-macos/", "published_at": "2019-01-31T21:21:12+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221b75b660", "title": "Sandboxed malware may control your pasteboard", "url": "https://wojciechregula.blog/post/sandboxed-malware-can-control-your-pasteboard/", "published_at": "2018-12-18T09:23:56+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221bb1e8a7", "title": "Newsletter", "url": "https://wojciechregula.blog/newsletter/", "published_at": "2018-12-08T21:24:29+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221beb1998", "title": "Your Signal messages can leak via locked screen on macOS", "url": "https://wojciechregula.blog/post/your-signal-messages-can-leak-via-locked-screen-on-macos/", "published_at": "2018-11-12T23:58:36+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221c1ecb7f", "title": "Clone your finger - bypassing TouchID", "url": "https://wojciechregula.blog/post/clone-you-finger-bypassing-touchid/", "published_at": "2018-08-21T21:42:37+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221cb29648", "title": "My thoughts after AppSec EU", "url": "https://wojciechregula.blog/post/my-thoughts-after-appsec-eu/", "published_at": "2018-07-09T17:23:42+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221cbbc642", "title": "Your encrypted photos revealed in macOS cache", "url": "https://wojciechregula.blog/post/your-encrypted-photos-in-macos-cache/", "published_at": "2018-06-02T13:24:51+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221d5601f1", "title": "Authenticated Code Execution in DASAN routers", "url": "https://wojciechregula.blog/post/authenticated-rce-in-dasan-routers/", "published_at": "2018-04-26T22:38:16+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221e288857", "title": "Story about hacking security conference and their funny revenge", "url": "https://wojciechregula.blog/post/playing-with-hacker-conf/", "published_at": "2018-04-09T10:02:41+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221ed5f3b9", "title": "Cordova keychain leak", "url": "https://wojciechregula.blog/post/cordova-keychain-leak/", "published_at": "2018-03-29T16:48:12+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55221f56f04a", "title": "FreePlane", "url": "https://wojciechregula.blog/post/freeplane-xxe/", "published_at": "2018-03-19T23:00:10+00:00" }, { "id": "01a08c63-9dd6-71c5-816a-55220ca201b1", "title": "About me", "url": "https://wojciechregula.blog/about-me/", "published_at": "2018-03-18T00:56:44+00:00" } ] posts Claim your blog
Back to wojciechregula.blog
Blog · corpus.blog/blogs/wojciechregula.blog/posts

wojciechregula.blog

wojciechregula.blog

2026

2024

2023

2022

2021

2020

2019

2018