CuraSec

Plan active

PoC: AppleKeyStore OOB read defeats KASLR on iOS 26.6

2026-09-04 14:56 UTC · GitHub Trending · read the source ↗ #ios#kaslr-bypass#public-poc
  • Engineer — Plan: A public PoC for a KASLR-defeating info leak on iOS 26.6 lowers the bar for full exploit chain development; audit MDM-enrolled iOS devices in your fleet and track Apple’s patch release for this build.
  • SOC/IR — Learn: A KASLR defeat primitive is a meaningful step toward mobile exploitation chains, but with no active campaign, no IOCs, and EPSS at 0.00, there is no detection or hunt action available yet.
  • Leader — Skip
  • Signals: CVE-2026-65343 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.