
kfd
kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices.

kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices.

Exploit for Apple CoreGraphics heap overflow (CVE-2014-4377) enabling arbitrary code execution on iOS 7.1.x via crafted PDF used as HTML image.

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

ANE kernel r/w exploit for iOS 15 and macOS 12

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

proof-of-concept for CVE-2023-28197

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

Exploit analysis for CVE-2014-4378: information disclosure in Apple CoreGraphics via crafted PDF, enabling memory layout leak and bypass of ASLR,…

Technical analysis of CVE-2026-28858, a critical buffer overflow in Apple iOS/iPadOS kernel, including exploit flow, mitigation, and defensive coding…

Technical analysis and exploit demonstration of CVE-2022-32898, a kernel memory corruption vulnerability in Apple Neural Engine driver, with detailed…

Technical writeup of CVE-2025-24104: an iOS sandbox escape via symlink validation bypass in backup restoration, enabling arbitrary file reads outside…

IOS audio buffer overflow CVE-2025-31200 POC

PoC CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability

Curated collection of security research papers, CVE exploit writeups, reverse-engineering analyses of Apple internals, and commissioned security…

Proof-of-concept exploit for CVE-2024-23208, targeting a specific vulnerability in Apple platforms. Provides a test case for security researchers and…

Kernel exploit for CVE-2026-43724 targeting Apple macOS/iOS systems. Provides proof-of-concept code for the disclosed vulnerability.

PoC CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability

Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)