PortsuppeApp
SearchSourcesAboutDE/EN

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

Google Project Zero·117d·Official

In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-free vulnerability (CVE-2025-31235) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability. I’ll explain the technical details of turning a potentially exploitable crash into a working exploit: a journey filled with dead ends, cr

Categories cybersecurity
Original source / advisory
Published
1/29/2026, 11:00:00 PM
Fetched
5/27/2026, 4:13:24 AM
Trust
official · 100/100
Language
en