In December last year, I released the async_wake exploit for iOS 11.1.2. In this talk, I’ll cover how each step of the exploit worked and discuss in depth each mitigation which was defeated along the way.
By Ian Beer
Full abstract: https://www.blackhat.com/us-18/briefings/schedule/#a-brief-history-of-mitigation-the-path-to-el1-in-ios-11-11569