theevilbit

How a single PostScript file leaks your Mac's memory

Intro#

When I started my InfoSec journey, most of the offensive classes I took focused on memory corruption exploits. About 8 years ago, I started learning about macOS, and from the beginning I approached it via logic bugs, and slowly I drifted further and further away from memory corruption work.

Then I read in Jonathan Levin's OS Internals books that Spotlight and QuickLook plugins involve a potential security risk, as file formats can be malformed in a nigh infinite number of ways. The idea stayed in the back of my mind for years. One day I decided to run a short side quest: I uploaded some decompiled functions from the PostScript Spotlight plugin, and asked Claude to find potential memory corruption issues in this parser.

And it did.

...

The full blog was published at my company's (Iru, formerly Kandji) website: https://www.iru.com/blog/how-a-single-postscript-file-leaks-your-macs-memory