黑客、渗透测试和网络安全工具,武装您的安全武器库!
PoC and technical details of CVE-2025-24204
发现我们社区最常用的工具。
探索所有工具
浏览我们的工具集合
CVE-2025-24204 是一个漏洞,允许在启用了 SIP 的 macOS 系统上读取任意进程的内存。此漏洞的根本原因在于向 gcore 二进制文件添加了过于强大的授权(com.apple.system-task-ports.read)。利用此漏洞可以实现:
gcore
com.apple.system-task-ports.read
Koh M. Nakagawa (@tsunek0h)。© FFRI Security, Inc. 2025
Apache 2.0 版本