Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
WebKit-Bug-256172 — Safari 1day RCE Exploit | Kitploit
Tools/GitHubGitHub/wh1te4ever/webkit-bug-256172
iOS SecurityExploitationShellcodeWeb SecurityMobile SecurityPayload DevelopmentBinary Exploitation
GitHubwh1te4ever/webkit-bug-256172

WebKit-Bug-256172

Safari 1day RCE Exploit

View Repository
165311 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

WebKit-Bug-256172

Safari 1day RCE Exploit, might be patched in iOS 16.5.1/macOS 13.4.1
Confirmed exploit works on macOS 13.3.1, iOS 15.8.2.

Description

Currently only works on macOS 13.0.1 (x86_64) due to hardcoded offsets.

  • Implemented addrof/fakeobj, r/w primitive
  • Patch SecurityOrigin->m_universalAccess to 1
  • Load stage1.bin by JIT Execution

Credit

  • ENKI WhiteHat for original PoC with detail writeup
  • saelo's jscpwn module
  • ret2 for building stage1.bin shellcode

Demo

  • https://www.youtube.com/watch?v=s9toRRQoWf4

Disclaimer

This repository is intended solely for educational purposes and should not be used for any malicious activities.
There's no way responsible for me to any misuse of this PoC.

Download Tool