Write-ups and blog posts
I’m a 19-year-old iOS security researcher from the UK. What started out as a hobby at 15 years old has become my full-time job, with me now being an iOS researcher at Cellebrite Labs. However, before that started, I enjoyed maintaining my blog and releasing public projects - and I still do today! While I may not do so as frequently anymore (I have far less free time than when I was in school), I try my best to make time for some of my more exciting external projects when I can.
I’ve written about various components of iOS - code-signing, kernel exploitation and PPL & SPTM to name a few. As part of these, I also delve into untethered code execution, attacking coprocessors and pushing both the hardware and the software inside these devices to the limit.
Projects
| Project | What it is |
|---|---|
| Trigon | Deterministic kernel exploit for iOS 16.5.1 and below |
| Titan | PPL & SPTM bypass for iOS 17.3.1 and below |
| ChOma | CoreTrust bypass for iOS 17.0 and below |
| Achilles | checkm8 implementation and PongoOS booter |
| TrollInstallerX | TrollStore installer for (almost) all TrollStore-supported devices |
| KextRW | macOS kernel extension for vulnerability research on current macOS |
Not everything gets released. I’ve also worked on an untethered jailbreak for iOS 14 and several kernel PAC bypasses. There are always future projects and write-ups in the works, so stay tuned! I will always announce new blog posts on my social media accounts, listed below.
Get in touch
There are various ways to find and/or contact me, and these are listed below. I will always be happy to discuss my blog posts, answer any questions or explain any concepts better if needed. Please don’t hesitate to get in touch!
- Email — [email protected]
- Twitter — @alfiecg_dev
- Mastodon — @[email protected]
- GitHub — @alfiecg24
- RSS — alfiecg.uk/feed.xml
Corrections are genuinely welcome. If something in a post is wrong, I’d rather know.
Posts
-
Trigon: exploiting coprocessors for fun and for profit (part 2)
-
Trigon: developing a deterministic kernel exploit for iOS (part 1)
-
A step-by-step guide to writing an iOS kernel exploit
-
An in-depth look at the code-signing process: ad-hoc signing
-
A comprehensive write-up of the checkm8 BootROM exploit
-
Getting untethered code execution on iOS 14.8
subscribe via RSS