Exploiting Reversing (ER) series: article 10 | iOS Security Research (part 01)

Today the tenth article in the Exploiting Reversing Series (ERS) is available. This new article has 205 pages, and it is free, like every article in the series.

Read it here, published on:

https://exploitreversing.com/wp-content/uploads/2026/10/exploit_reversing_10.pdf

This is the first article in the series aimed at iOS itself, and it opens a multi-part sequence on iOS security research.

Most writing on iOS exploitation assumes the reader already has a paired device, a relaxed Mac host and a symbolicated kernelcache. This article deliberately starts earlier than that, because the environment you build at the beginning filters everything that follows.

It covers:

[+] The protection stack a kernel chain must cross in sequence: KASLR, Pointer Authentication, kalloc_type segregation with zone_require assertions, PPL and its successors SPTM at GL2 and TXM at GL0, Exclaves, and trust-cache code signing — and why each layer pushes modern exploitation further toward data-only technique.

[+] Reachability, the question that decides whether a bug is worth anything: Of roughly 140 IOKit services on a current device, only eighteen can be opened from inside the application sandbox. The article works through sandbox_check probing, what entitlements enforce that a sandbox profile cannot, and an empirical sweep of which user clients actually open and which selector types they accept.

[+] The four roles of a working 2026 research lab: an orchestrating workstation, an Apple Silicon Mac host with SIP disabled and AMFI relaxed, a vPhone guest running a jailbroken image under Apple’s Virtualization.framework, and physical iPhones where a finding gets its last word.

[+] A reproducible kernelcache pipeline: symbolication with ipsw and the Cellebrite IDA plugins, export of the IDB into SQLite so the kernel becomes queryable across builds, and four approaches to diffing two kernelcaches or two IPSWs.

The primary source for new articles is https://www.blackstormsecurity.com/research/, but articles will continue to be published here with a week of delay.

I would like to thank Ilfak Guilfanov (@ilfak) and Hex-Rays SA (@HexRaysSA) for the continuous support.

Enjoy the reading and have an excellent day.

Alexandre Borges

(October 06, 2026)

#iOS #VulnerabilityResearch #ExploitDevelopment #ReverseEngineering #KernelSecurity

The start

“Long is the way and hard, that out of hell leads up to light.”

(by John Milton from Paradise Lost — 1667)

My name is Alexandre Borges and I’m a security researcher focused on reverse engineering, exploit development and programming. Therefore, I’ll try to keep this blog updated and including write-up’s about these topics.

Honestly, I hope you can learn something from my posts.

Please, you should feel free to contact me and comment about any mistake and inaccuracy.

Have an excellent day.

A.B.