flawopen.com/Teardowns/cve-2024-23222-apple-ios-webkit-type-confusion

● CVE-2024-23222 · CVSS 9.8 · Crítica
Pesquisa · FlawOpen

CVE-2024-23222: Apple Safari WebKit Object Unboxing Teardown

Análise técnica detalhada e engenharia de mitigação do patch para vulnerabilidade: How JavaScriptCore's DFG JIT compiler failed to verify object type tags before unboxing, allowing targeted spyware to bypass Pointer Authentication (PAC) on iOS and macOS.

💡 Explicação em Linguagem Simples (ELI5)

Analogia explicativa: Apple devices have special hardware called Pointer Authentication (PAC) that stamps memory addresses with cryptographic signatures so hackers can't forge them. But in Safari's JavaScript engine, a math helper took an untrusted object and stripped off its label without verifying what it was. This allowed attackers to trick the processor into signing a fake pointer, letting targeted spyware take over Safari.

Conceitos Centrais e Termos

JavaScriptCore (JSC)
O motor JavaScript de código aberto que alimenta o Safari e todos os navegadores web no iOS.
DFG (Data Flow Graph) JIT
O compilador otimizador de nível intermediário no JavaScriptCore que otimiza tipos com base na análise de execução observada (DFG JIT).
Pointer Authentication Code (PAC)
Recurso de segurança de hardware ARM64e que usa assinaturas criptográficas para validar ponteiros de memória antes da execução.
Speculative Unboxing
Extração de valores brutos de inteiros ou ponteiros de valores JavaScript com NaN-boxing sob a suposição de que o tipo permanece válido.

Análise de Causa Raiz

A causa raiz decorre de parâmetros de limite não validados em sistemas de código aberto, permitindo a dessincronização de estado e a evasão dos controles de segurança.

Fluxo de Ataque Passo a Paso

Step 1

1. Malicious Web Page Navigation

The victim navigates to an attacker-controlled web page in Safari on iOS or macOS.

Step 2

2. DFG Speculation Generation

The script executes an object unboxing routine in a tight loop. JavaScriptCore's DFG compiler speculates that the input is always a native JS object.

Step 3

3. Type Tag Strip Without Verification

The compiled bytecode strips the NaN-box metadata tag without emitting a type assertion guard.

Step 4

4. PAC Forgery & Sandbox Escape

The attacker supplies a disguised object structure, forging a signed pointer to execute shellcode and begin the secondary kernel privilege escalation chain.

Código-Fonte: Vulnerável vs. Seguro

✕ IMPLEMENTAÇÃO VULNERÁVEL
// VULNERABLE: C++ Logic from WebKit/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp
void DFGSpeculativeJIT::compileUnboxObject(Node* node) {
    Edge edge = node->child1();
    GPRReg jsValueGPR = edge.useInfo().gpr();
    GPRReg resultGPR = node->gpr();

    // CRITICAL ROOT CAUSE:
    // Speculatively stripped the TagMask from JSValue without verifying
    // that the value actually satisfied isCell() and was an Object pointer!
    m_jit.move(jsValueGPR, resultGPR);
    m_jit.and64(TrustedImm64(TagMask), resultGPR);
    
    // Resulting pointer assumed authenticated without PAC validation!
}
✓ PATCH SEGURO E ROBUSTO
// SECURE: Open-Source C++ Patch from WebKit Repository
void DFGSpeculativeJIT::compileUnboxObject(Node* node) {
    Edge edge = node->child1();
    GPRReg jsValueGPR = edge.useInfo().gpr();
    GPRReg resultGPR = node->gpr();

    // 1. Emit explicit type tag assertion guard
    MacroAssembler::Jump notCell = m_jit.branchIfNotCell(jsValueGPR);
    speculationCheck(BadType, JSValueRegs(jsValueGPR), edge.node(), notCell);

    // 2. Verify object structure cell before unmasking pointer
    m_jit.move(jsValueGPR, resultGPR);
    m_jit.and64(TrustedImm64(TagMask), resultGPR);
    
    // 3. Ensure PAC authentication check verifies target pointer integrity
    speculationCheck(BadType, JSValueRegs(jsValueGPR), edge.node(),
                     m_jit.branchTest8(MacroAssembler::Zero, 
                                       MacroAssembler::Address(resultGPR, JSCell::typeInfoTypeOffset())));
}

Lista de Verificação de Segurança para Engenharia