Researchers detailed two Safari WebKit exploitation paths that turned renderer memory corruption into reliable arbitrary read/write primitives on macOS and iOS. Google Project Zero showed how CVE-2020-9802, a JavaScriptCore JIT flaw, could be exploited starting from addrof and fakeobj primitives, then bypass WebKit mitigations including StructureID randomization, the Gigacage, and PACCage. The write-up demonstrated leaking a valid StructureID with a fake JSArray and then abusing TypedArray handling in the DFG JIT to escape the Gigacage and gain fast, stable arbitrary memory access.
Theori separately analyzed a Safari AudioWorklet type confusion introduced in Safari 14.1, where WebKit failed to verify that a returned JavaScript object was a JSAudioWorkletProcessor. That missing type check allowed attacker-controlled objects to be confused and used to corrupt JSArray butterfly pointers, again yielding addrof, fakeobj, and arbitrary read/write capabilities. The exploit reportedly worked on iOS 14.6 and macOS 11.4 even after the source patch was public, highlighting patch-gap risk and reinforcing concerns that existing WebKit hardening measures could still be bypassed in practice.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Theori published an analysis of a Safari AudioWorklet type confusion vulnerability in WebKit, explaining that the bug was introduced with Safari 14.1 and that a missing jsDynamicCast check enabled memory corruption and exploitation. The write-up said the exploit remained reachable on iOS releases after the patch became public and reportedly worked on iOS 14.6 and macOS 11.4.
Google Project Zero published the second part of its JITSploitation series, detailing how to turn a JavaScriptCore JIT bug tracked as CVE-2020-9802 into stable arbitrary memory read/write in Safari despite mitigations such as StructureID randomization, the Gigacage, and the PACCage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.