Our core practice. We find original vulnerabilities in modern, mitigated software and turn them into reliable, reproducible exploits.
Research Targets
- iOS — userland services, IPC and attack surface reachable from unprivileged contexts, plus XNU kernel research against PAC, KTRR/CTRR, PPL and SPTM.
- Android — system services and Binder interfaces, media and driver attack surface, Linux kernel exploitation against SELinux, seccomp and hardened allocators.
- Google Chrome — V8 and Blink renderer exploitation, IPC/Mojo attack surface, and sandbox escape leading to full chains.
- Windows — kernel and driver research, win32k and IOCTL attack surface, userland services, and applications running on Windows.
- Hypervisors — device emulation and paravirtualized interfaces, guest-to-host escape research.
How We Work
Attack surface mapping. Every engagement starts with reverse engineering the target to identify reachable, security-relevant code — trust boundaries, parsers, privileged interfaces and the code paths an attacker can actually influence.
Bug hunting. Coverage-guided and structure-aware fuzzing with custom harnesses, combined with manual auditing of the code paths that automated tooling handles badly: state machines, reference counting, race conditions and logic flaws.
Triage and root cause analysis. Each crash is reduced to a minimal reproducer and analysed until the underlying defect, its primitives and its reachability are fully understood — not just its symptom.
Exploitation. Converting a primitive into reliable code execution against current mitigations: heap grooming and allocator manipulation, info leaks to defeat ASLR, control-flow integrity and pointer authentication bypass, data-only attacks where control-flow hijacking is impractical, and sandbox escape to reach the target privilege level.
Reliability engineering. Research-grade proof of concept is where most work stops. We continue until the exploit is deterministic across target versions and device configurations, degrades safely on failure, and leaves the target stable.
Deliverables
- Complete technical report: root cause, affected versions, reachability and impact.
- Working exploit with documented primitives and success-rate measurements.
- Reproduction environment and build instructions.
- Walkthrough session with your engineering team.
Discuss an engagement: contact@blackstormsecurity.com