PUBLIC NOTES ON iOS SECURITY
iossec.tech
Low-level vulnerability research across iOS — from kernel internals to system services.
Vladislav Shevchenko is a fourth-year Information Security student at HSE University and an iOS vulnerability researcher at Positive Technologies. His work spans kernel internals, Apple Neural Engine, M2Scaler, and platform mitigations.
Selected
findings.
Public write-ups, PoCs and root-cause analyses. The complete collection lives in CaseStudies ↗
CVE-2026-43748 — Kernel heap OOB write in the ANE direct path
PoCs and root-cause analysis for CVE-2026-43748 in ANE_ProgramCheckandPrewireBuffers_gated.
CVE-2026-39868 — Kernel memory corruption in DTrace DOF helper parsing
Malformed lazy DOF sections, integer overflows, and a confused-deputy path into fasttrap qsort.
CVE-2026-65371 — Kernel address leak in IOService::updateConsoleUsers
A gRegistryRoot kernel address reaches user space through console-security interest notifications.
IOSurface KVA and MTE-tag disclosure
An unsanitized diagnostic-log payload exposes a chosen IOSurface address and its MTE tag.
Sandbox escape via c.a.f.netfs.PlugInLibraryService
Unsandboxed NetFS plugin loading via path traversal and CFPlugIn abuse.
Bug in dyld4::setUpPageInLinkingRegions
A TPRO-stack overflow edge case in dyld4::setUpPageInLinkingRegions.
How I move through
millions of lines.
A mix of open-source tools I host or adapt, plus custom infrastructure built around day-to-day iOS research.
cs.iossec.tech
Hosted Elixir Code Search for the iOS kernel and dyld, with a few local tweaks.
↗U—02zoekt.iossec.tech
A hosted Zoekt instance for fast regex search across iOS kernel source.
↗U—03panic.iossec.tech
A custom receiver for collecting iOS crash reports and kernel panics.
↗Found something
strange?
Feel free to DM me through whichever channel works best for you.