Joseph Goydish II

Expert
@JGoyd

When trust fails, all we have left is each other.

iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201. CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).

198

Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201. Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then WebKit(CVE-2025-24201) and Core Media(CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.

40

iOS-18.5-Bluetooth-Privacy-Vuln. Discovery of a critical Bluetooth and GPS privacy vulnerability in iOS 18.5 enabling silent BLE scans, covert GPS activation, and trust metadata exposure without user consent. Native Apple daemons bypass TCC and cryptographic checks, violating expected iOS privacy guarantees.

27

iOS18.6.2-Persistent-Automation-Exploit-in-Siri-Shortcuts-and-Apple-SWC. This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger retry storms, bypass TLS validation, and request unauthorized entitlements. Confirmed on iOS 18.6.2 with potential iCloud-based propagation.

16

A16-FuseBypass. This repository discloses a critical vulnerability in Apple’s A16 Bionic chip, where debug logic is executed on production-fused devices (dev-fused=0, debug=0x0). Logs show SecureROM and co-processor debug paths active without jailbreak or user tampering—violating the silicon-level trust model.

16

Apple-Silicon-A17-Flaw. Forensic hardware research and audit tools uncovering vulnerabilities in A17 Pro silicon.

14

ZombieHunter. Python

10

Undocumented-System-Behavior-in-iOS-18.6-Silent-TCC-Bypass-and-Data-Movement. Silent TCC bypass in iOS 18.6 allows Apple daemons to access protected data, modify sensitive settings, and exfiltrate ~5MB of data over the network—without user interaction, apps, or prompts. Logged via native tools, this behavior is invisible to users and MDMs. Caught in the wild.

6

THREAT-INTEL-odoh-beaconing-analysis. Suspicious ODoH-based DNS beaconing was observed on a non-jailbroken iOS 18.6.2 device. Apple-signed system processes initiated encrypted queries every 60 seconds, triggered by Bluetooth events. The behavior suggests covert telemetry or spyware leveraging system-trusted execution paths.

5

iOS-DFU-Persistence. Meta-data doesn't lie. The truth doesn't hide.

5

Fourteen_Endpoints. Shell Companies Inside Apple's Privacy Relay

5

iOS-Activation-Flaw. A critical vulnerability in Apple’s iOS activation backend allows injection of unauthenticated XML .plist payloads during the device setup phase. The flaw permits arbitrary provisioning changes without authentication, signature verification, or error feedback; exposing devices to pre-activation tampering & persistent configuration manipulation.

4

NeuralNet. Forensic analysis of a kernel-level autonomous mesh (NeuralNet) that bypasses Airplane Mode. Evidence confirms hardware status deception (AWDL active while "inactive"), unauthorized 84.5MB data transport, and persistent shadow tunnels (utun2). Verified via Shannon-Hartley theorem.

4

THREAT-INTEL-ios-covert-intrusion-lifecycle. Detailed analysis of covert intrusion techniques in iOS 18.6.2, featuring memory-resident implants, AWDL peer comms, Lockdown abuse, and cloud-layer persistence. High stealth persistence and forensic evasion mapped to MITRE ATT&CK. Threat profiling suggests red-team or APT-grade capabilities.

3

ams-failopen. Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade, replay, and bypass risk. Includes analysis, log evidence, and PoC attack logic.

3

ios-trust-collapse. iOS 18.6.2 suffers from broken encryption caused by a trust subsystem failure. Malformed anchor records and ATS disablement allow TLS connections to succeed without certificate validation, exposing WebKit, CloudKit, and more to interception, spoofing, and data compromise.

3

THREAT-INTEL-Apple-System-Spoofing-C2. Technical threat report detailing post-exploitation C2 activity on iOS using Apple system service spoofing, TLS 1.3 traffic, and reflective binary loading. Includes full analysis, logs, and behavioral indicators for investigation.

3

iOS-TCC-Framework-Bypass.

3

A18-AON_Design. Structured disclosure and Mach-O dissection of Apple A18 Always-On (AON) processor design.

3

The-Autopen. Implant Anatomy, Single Device. iPhone 12, iOS 26.4.

3

MapleDrop. Architectural analysis and threat modeling of bag distribution mechanisms at Apple.

3

RemoteRAT. Technical threat intelligence analysis of Remote Access Trojan (RAT) campaigns and indicators.

3

Global-Audio-Hardware-Risk. Critical hardware vulnerability in the CS42L7x audio coprocessor affects 500+ million devices. Malicious audio files can bypass memory protections, compromise consumer and industrial systems, and cannot be fully mitigated by software updates.

2

BroadScope.

2

dfu-hardware-gap-cs35l2.

2

Same_Place-Different_Time.

2

Shattered-Glass. Python

2

Ghost-Push-Background-Delivery-via-Expired-APNs-Tokens. This repo documents a flaw where APNs delivered push notifications using a cached, expired token—despite failed token lookups and no app re-registration. Background daemons processed the message without an active app context, enabling covert push behavior and violating expected token lifecycle rules.

1

Triangulation-Killswitch.

1

ShadowShells. Indicators of a hidden mesh, traced through echoes and signals — a codex of activity for those who watch.

1

iDrive-Exfil. FBI(IC3) Submission ID: 067b3177c3524c80bce02cca08064d11

1

Snapdragon-X65-Telemetry-Overflow.

1

Tunnel-Vision. Python

1

m365-mime-type-confusion. Security disclosure identifying MIME type confusion vulnerabilities within Microsoft 365.

1

datalytic-shadow-collectors. Python

1
35
Apply