A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
12 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains an iOS/macOS application project named 'JailedCement', written in Swift and Objective-C. The main exploit logic is in 'BrickerFunctions.swift', which defines a 'brick()' function. When triggered (e.g., via a button in the SwiftUI 'ContentView'), this function attempts to corrupt a critical system plist file and then wipe the root filesystem. The Objective-C code in 'deadbeef.m' provides low-level file and memory manipulation functions used by the Swift code. The exploit is designed to render the device unbootable (bootloop) by destroying essential system data. The project includes standard Xcode project files, test files, and asset files, but the core exploit is in the Swift and Objective-C source files. No network endpoints are present; the attack is purely local and destructive. The exploit is operational, not a PoC, as it contains a working payload that can brick a device if executed.
This repository contains 'Mandela', an iOS customization app that exploits CVE-2022-46689 (vm_unaligned_copy_switch_race) to enable system modifications on iOS devices without requiring a jailbreak. The project is written primarily in Swift, with supporting Objective-C and C code for the exploit and helper functions. The app provides a GUI for users to perform various system tweaks, including changing the carrier name, device type, system license (replacing it with a custom HTML, e.g., DOOM), enabling/disabling the mute switch in Control Center, changing screen resolution, and toggling device supervision status. The exploit works by overwriting protected system files using a race condition in the kernel, and includes mechanisms to gain unsandboxed access via a tccd hijack. The codebase is modular, with each tweak implemented as a separate SwiftUI view, and core exploit logic in supporting C/Objective-C files. The app is intended for iOS 15+ devices that are vulnerable to CVE-2022-46689 and can be installed via TrollStore or similar methods. The repository includes build scripts, Xcode project files, and documentation for extending the app with additional 'mods.' No network endpoints are present; all actions are performed locally on the device.
This repository contains 'Mandela', an iOS app that leverages CVE-2022-46689 (a kernel race condition) to enable system-level customizations on iOS devices without requiring a jailbreak. The app is written in Swift, Objective-C, and C, and is structured as an Xcode project with supporting scripts and entitlements. The core exploit is implemented in 'Mandela/Exploit/vm_unaligned_copy_switch_race.c' and 'grant_full_disk_access.m', which allow the app to overwrite protected system files and grant itself full disk access. The app provides a user interface for various tweaks, such as changing the device type, modifying system sounds, altering the license file, and changing screen resolution, by overwriting or modifying specific system files and plists. The exploit is operational and can be used on iOS 15 and 16.0/16.1 devices that are vulnerable to CVE-2022-46689. The repository includes all necessary code, entitlements, and build scripts to compile and deploy the app.
This repository contains a single Metasploit module (mac_dirty_cow.rb) that exploits CVE-2022-46689, a local privilege escalation vulnerability in macOS (Dirty Cow). The exploit works by leveraging a race condition in the kernel to overwrite arbitrary files, specifically targeting the PAM configuration file (/etc/pam.d/su) to allow privilege escalation. The module uploads a payload (default: osx/x64/shell_reverse_tcp) to a writable directory (default: /tmp), modifies the PAM file to permit privilege escalation, executes the payload as root, and then restores the original file. The exploit is operational and requires local access to a vulnerable macOS system. The only endpoints involved are local file paths, and there is no network targeting. The code is written in Ruby and is designed to be run within the Metasploit Framework.
This repository contains a proof-of-concept local privilege escalation exploit for macOS 13.0.1 and 12.6.1 (and below), targeting CVE-2022-46689 (the 'macdirtycow' bug, a macOS equivalent of Dirty COW). The exploit is implemented in C (vm_unaligned_copy_switch_race.c) and leverages a race condition in the virtual memory subsystem to overwrite read-only files, such as /etc/pam.d/su. The README provides detailed usage instructions, including compiling the exploit, preparing an overwrite file, and executing the exploit to gain root privileges by bypassing authentication. The exploit requires local access and works even with System Integrity Protection enabled, though changes to files on the /System volume are reverted on reboot. The repository is structured with a single exploit source file and a README, and does not use any exploit framework.
This repository contains a proof-of-concept (PoC) exploit for CVE-2022-46689, also known as MacDirtyCow, a local privilege escalation vulnerability in macOS's XNU kernel. The repository consists of two files: a README.md explaining the vulnerability and the PoC, and poc.c, which implements the exploit. The C code takes a file path as an argument, memory-maps the file, modifies the mapped memory to fill it with 'A' characters, and writes the changes back to the file, demonstrating the ability to overwrite read-only files by exploiting a race condition in the kernel's copy-on-write mechanism. The exploit requires local access and targets a user-supplied file path, making it a local attack vector. The code is a minimal PoC and does not provide a weaponized payload, but it effectively demonstrates the vulnerability's impact.
This repository is a proof-of-concept (PoC) exploit for CVE-2022-46689, a race condition vulnerability in Apple's iOS kernel that allows attackers to overwrite arbitrary files. The project is structured as an Xcode project for iOS, containing Swift UI code for a file manager interface and C code implementing the low-level race condition exploit. The main exploit logic is in 'files/ContentView.swift', which provides a file manager UI and invokes the 'overwriteFile' function to exploit the vulnerability. The actual race condition is implemented in 'files/vm_unaligned_copy_switch_race.c' and exposed to Swift via a bridging header. The exploit allows a user to select a file and overwrite its contents with attacker-controlled data, bypassing normal file system protections. The attack vector is local, requiring code execution on a vulnerable device. No network endpoints are present; the main fingerprintable endpoints are file paths, especially the root '/' and arbitrary victim file paths. The repository is a functional PoC and not a weaponized exploit.
This repository contains an iOS application, FileSwitcherX, which exploits the MacDirtyCow vulnerability (CVE-2022-46689) to overwrite protected system files on iOS devices running versions 14.0-15.7.1 and 16.0-16.1.2. The exploit is implemented in a combination of Swift, Objective-C, and C, with the core logic residing in the 'exploit' directory (poc.m, vm_unaligned_copy_switch_race.c/h). The app provides a GUI for selecting and overwriting specific system files, such as UI assets (e.g., /System/Library/PrivateFrameworks/MaterialKit.framework/Assets.car) and material recipe files for the dock. The exploit works by mapping the target file into memory and using a race condition in the kernel's memory management to bypass write protections. The app is intended for use on devices where the user can install unsigned apps (e.g., via TrollStore or AltStore). The repository is structured as a standard Xcode project, with the main logic in Swift files and the exploit code in the 'exploit' subdirectory. The exploit is operational and allows for real modification of system files, but is not weaponized for remote or automated attacks.
This repository contains an iOS application ('NoCameraSound') and a helper app ('NoCameraSound_Opener') designed to exploit the MacDirtyCow vulnerability (CVE-2022-46689) on iOS 14.0-15.7.1 and 16.0-16.1.2. The main exploit is implemented in Swift and C, with the core logic in 'NoCameraSound/NoCameraSound/ContentView.swift', 'NoCameraSound/NoCameraSound/NoCameraSound.swift', and 'NoCameraSound/NoCameraSound/vm_unaligned_copy_switch_race.c'. The exploit works by overwriting protected system audio files responsible for the camera shutter and recording sounds, effectively silencing them. The overwrite is performed using a kernel race condition, allowing modification of files that are normally protected. The app provides a user interface to disable or restore the shutter sound, and includes logic to check if the overwrite was successful. The 'NoCameraSound_Opener' app appears to assist with running the main app or its shortcut. The exploit is operational and requires installation via TrollStore or AltStore. No network endpoints are present; all actions are performed locally on the device. The targeted files are clearly listed and fingerprintable. The repository is not part of a known exploit framework and is a standalone operational exploit for iOS devices vulnerable to MacDirtyCow.
This repository contains an iOS application called 'NoHomeBar' that leverages the MacDirtyCow (CVE-2022-46689) exploit to disable or restore the HomeBar UI element on iOS devices running versions 14.0 to 16.1.2. The main exploit logic is implemented in Swift (NoHomeBar/ContentView.swift, NoHomeBar/NoHomeBar.swift) and C (NoHomeBar/vm_unaligned_copy_switch_race.c, .h). The exploit works by overwriting the system file /System/Library/PrivateFrameworks/MaterialKit.framework/Assets.car with custom data, using a race condition in the kernel to bypass file protections. The app provides a user interface to trigger the exploit and restore functionality, and includes references to the original MacDirtyCow exploit. The repository is structured as an Xcode project, with Swift UI code, C exploit code, and supporting assets. The exploit is operational and can be used to modify protected system files on vulnerable iOS devices, with changes persisting until the device is rebooted.
This repository is a proof-of-concept exploit and app for CVE-2022-46689, a race condition in the Apple iOS kernel that allows local attackers to overwrite read-only files on the filesystem. The exploit is implemented as an iOS app (Swift/Objective-C) that enables users to overwrite system font files (including emoji fonts) on iOS 16.1.2 and below, without requiring a jailbreak. The app provides a user interface for selecting and importing custom fonts, and includes scripts and utilities for preparing font files in the WOFF2 format with special padding to bypass the exploit's limitation (cannot overwrite the last byte of each 16KB page). The core exploit logic is in 'OverwriteFontImpl.swift', which uses a race condition (implemented in C as 'vm_unaligned_copy_switch_race.c') to perform the overwrite. The repository also includes Objective-C code to grant full disk access and clear keyboard caches. The exploit targets system font files such as '/System/Library/Fonts/CoreUI/SFUI.ttf' and '/System/Library/Fonts/Core/AppleColorEmoji.ttc'. The repository is operational and provides a working exploit for the specified iOS versions, with a focus on font replacement as the payload.
This repository contains an iOS application called DockTransparent, which leverages the MacDirtyCow (CVE-2022-46689) exploit to overwrite protected system files on iOS devices (versions 14 to 16.1.2). The main purpose is to make the Dock transparent by modifying the material recipe files used by the system Dock. The application is written in Swift, with a C component implementing the low-level exploit logic. The main files of interest are ContentView.swift (UI and logic), DockTransparent.swift (file overwrite logic), and vm_unaligned_copy_switch_race.c/h (the exploit implementation). The app provides a user interface to apply or restore the modification, and includes checks to determine if the overwrite was successful. The exploit is operational and not just a proof of concept, as it provides a full user interface and restoration capability. The targeted files are /System/Library/PrivateFrameworks/CoreMaterial.framework/dockDark.materialrecipe and dockLight.materialrecipe. The exploit requires the device to be vulnerable to MacDirtyCow and does not work on iOS 14. The repository is not part of a larger exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.