
We found a KASLR bypass in macOS IOKit. Two services leaked live kernel heap addresses to any unprivileged, sandboxed user. Apple Security Bounty, CVE-2026-20695, fixed in macOS Tahoe 26.4. This is the exact process we teach in our new course: macOS Kernel Vulnerability Research. Built from 10+ years of real bounty hunting on the kernel and beyond, not theory. Course: https://macseclabs.com/curriculum?course=macos-kernel-vulnerability-research Writeup: https://hxr1.ghost.io/leaking-the-kernel-a-kaslr-bypass-in-macos-iokit/ #RedTeam #macOS #OffensiveSecurity #CyberSecurity #InfoSec #EthicalHacking #PenTesting #SecurityTraining #BugBounty
Post summary
The post announces the discovery of a KASLR bypass in macOS IOKit (CVE‑2026‑20695), notes its patch in macOS Tahoe 26.4, and links to a writeup providing a PoC, framing it as a new vulnerability disclosure.


