A Year Fuzzing XNU Mach IPC

A year's worth of targeted fuzzing against XNU's Mach IPC subsystem — methodology, findings, and lessons learned.

Hexacon 2023
View slides

Talk delivered at Hexacon 2023 (Paris, October 2023), covering a sustained fuzzing campaign against XNU’s Mach IPC subsystem. The presentation walks through the fuzzer architecture, corpus construction, bug triage, and a selection of findings uncovered over the course of the year.

Slides available on GitHub