EP28 macOS Security Internals: Kernel Exploitation, PAC Defenses, and the Rise of macOS Infostealers with Olivia Gallucci
In this episode, we're joined by security researcher Olivia Gallucci to explore macOS low-level security, kernel exploitation, and macOS threat trends. We break down how macOS internals differ from Linux—focusing on IOKit, C++ dynamic class resolution, and Vtable hijacking in kernel drivers. Olivia explains the mechanics behind use-after-free (UAF) vulnerabilities, heap shaping, and legacy kernel exploits, as well as modern Apple hardware and OS defenses like Pointer Authentication Codes (PAC) and kalloc type isolation (PAC IA/DA semantics). We also discuss the evolution of macOS threat research, the rise of macOS info stealers driven by cryptocurrency targeting, local detection telemetry using Endpoint Security (ES) and tools like Mac Monitor, and the current dynamics of vulnerability research and bug bounty programs. Key Discussion Points: Mac vs. Linux Internals: Why macOS isn't "just Linux," and how IOKit’s C++ driver framework creates unique attack surface. Vtable Hijacking & Kernel Exploits: How dynamic method resolution and C++ polymorphism are targeted using UAF, out-of-bounds writes, and heap shaping. Modern Defenses: How Apple leverages Pointer Authentication Codes (PAC IA/DA) and type-isolated heap allocators to disrupt traditional exploit primitives. The Rise of macOS Infostealers: What drove the surge in macOS stealer malware, their simple architecture, and social engineering delivery tactics. Detection & Telemetry: Monitoring local exploit failures, kernel panics, and process events via Endpoint Security (ES Logger) and open-source tools like Mac Monitor. Vulnerability Research Ecosystem: The role of AI in technical research, shifting bug bounty payouts, and the dynamics between vendor programs and third-party research. Resources mentioned: Olivia Gallucci's Blog: oliviagallucci.com Mac Monitor by Brandon Dalton: https://github.com/Brandon7CC/mac-monitor Join the Community Research Hub: Threat research, training events and news: https://cloud.google.com/security/flare The FLARE Insider: Get community updates and announcements. To subscribe, email flare-external@google.com FOLLOW THE SHOW: Subscribe: Apple Podcasts | Spotify | YouTube