Exploiting Reversing (ER) series: article 10 | iOS Security Research (part 01)

Today the tenth article in the Exploiting Reversing Series (ERS) is available. This new article has 205 pages, and it is free, like every article in the series.

Read it here, published on:

https://exploitreversing.com/wp-content/uploads/2026/10/exploit_reversing_10.pdf

This is the first article in the series aimed at iOS itself, and it opens a multi-part sequence on iOS security research.

Most writing on iOS exploitation assumes the reader already has a paired device, a relaxed Mac host and a symbolicated kernelcache. This article deliberately starts earlier than that, because the environment you build at the beginning filters everything that follows.

It covers:

[+] The protection stack a kernel chain must cross in sequence: KASLR, Pointer Authentication, kalloc_type segregation with zone_require assertions, PPL and its successors SPTM at GL2 and TXM at GL0, Exclaves, and trust-cache code signing — and why each layer pushes modern exploitation further toward data-only technique.

[+] Reachability, the question that decides whether a bug is worth anything: Of roughly 140 IOKit services on a current device, only eighteen can be opened from inside the application sandbox. The article works through sandbox_check probing, what entitlements enforce that a sandbox profile cannot, and an empirical sweep of which user clients actually open and which selector types they accept.

[+] The four roles of a working 2026 research lab: an orchestrating workstation, an Apple Silicon Mac host with SIP disabled and AMFI relaxed, a vPhone guest running a jailbroken image under Apple’s Virtualization.framework, and physical iPhones where a finding gets its last word.

[+] A reproducible kernelcache pipeline: symbolication with ipsw and the Cellebrite IDA plugins, export of the IDB into SQLite so the kernel becomes queryable across builds, and four approaches to diffing two kernelcaches or two IPSWs.

The primary source for new articles is https://www.blackstormsecurity.com/research/, but articles will continue to be published here with a week of delay.

I would like to thank Ilfak Guilfanov (@ilfak) and Hex-Rays SA (@HexRaysSA) for the continuous support.

Enjoy the reading and have an excellent day.

Alexandre Borges

(October 06, 2026)

#iOS #VulnerabilityResearch #ExploitDevelopment #ReverseEngineering #KernelSecurity

Exploiting Reversing (ER) series: article 04 | macOS/iOS (part 01)

The fourth article (126 pages) of the Exploiting Reversing Series (ERS), a step-by-step research series on Windows, macOS, hypervisors and browsers, is available for reading on:

I would like to thank Ilfak Guilfanov (@ilfak on X) and Hex-Rays SA (@HexRaysSA on X) for their constant and uninterrupted support, which have helped me write these articles.

The best thing in life is people.

I hope you enjoy reading it and have an excellent day.

Alexandre Borges.

(FEBRUARY/04/2025)

Malware Analysis Series (MAS): article 08 | MacOS/iOS

The eighth article (62 pages) in the Malware Analysis Series (MAS), a step-by-step malware analysis and reverse engineering series, is available for reading on:

(PDF): https://exploitreversing.com/wp-content/uploads/2024/08/mas_08-1.pdf

I hope this article helps professionals from cybersecurity community around the world.

Have an excellent and keep reversing!

Alexandre Borges

(AUGUST/07/2024)