
CVE-2016-7624 — TOCTOU в IOKit (драйверная подсистема ядра iOS). Исследователь из Tencent Keen Lab обнаружил, что когда IOKit принимает дескриптор памяти от пользовательской программы, эта программа может менять содержимое прямо в момент обработки сервисом — без блокировок и защиты от записи . Идеальная почва для гонок. Дыра нашлась в IOCommandQueue::submit_command_buffer — данные атакующего сначала проверялись, а потом использовались, и в этот зазор можно было их подменить. Привело к повышению привилегий до ядра. CVE-2016-7624 — TOCTOU in IOKit (an iOS kernel driver subsystem). A researcher from Tencent Keen Lab discovered that when IOKit accepts a memory descriptor from a user program, that program can modify its contents directly while the service is processing it, without locks or write protection. This creates a perfect breeding ground for race conditions. The vulnerability was found in IOCommandQueue::submit_command_buffer — the attacker's data was first validated and then used, allowing it to be substituted during this gap. This resulted in privilege escalation to the kernel.
Post summary
The text announces a TOCTOU race condition in iOS IOKit that allows privilege escalation, providing technical details but no PoC, exploit, mitigation, or active exploitation evidence.
