<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml"><url><loc>/about-me/</loc><lastmod>2018-03-18T00:56:44+00:00</lastmod></url><url><loc>/tags/cve-2022-26767/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/tags/macos/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/post/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/tags/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/tags/tcc/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/post/tcc-bypasses-via-launch-services/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/tags/vulnerability/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/</loc><lastmod>2024-10-20T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2023-32422/</loc><lastmod>2024-06-24T10:37:00+00:00</lastmod></url><url><loc>/post/multiple-tcc-bypasses-via-sqlite-env-vars/</loc><lastmod>2024-06-24T10:37:00+00:00</lastmod></url><url><loc>/tags/electron/</loc><lastmod>2024-01-23T10:37:00+00:00</lastmod></url><url><loc>/post/electroniz3r/</loc><lastmod>2024-01-23T10:37:00+00:00</lastmod></url><url><loc>/tags/macos-red-teaming/</loc><lastmod>2024-01-23T10:37:00+00:00</lastmod></url><url><loc>/tags/atlassian/</loc><lastmod>2023-07-09T10:37:00+00:00</lastmod></url><url><loc>/tags/atlassian-companion/</loc><lastmod>2023-07-09T10:37:00+00:00</lastmod></url><url><loc>/post/macos-atlassian-companion-rce/</loc><lastmod>2023-07-09T10:37:00+00:00</lastmod></url><url><loc>/tags/rce/</loc><lastmod>2023-07-09T10:37:00+00:00</lastmod></url><url><loc>/post/bypass-tcc-via-icloud/</loc><lastmod>2023-03-04T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2021-30654/</loc><lastmod>2023-03-04T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2021-30757/</loc><lastmod>2023-03-04T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2022-32877/</loc><lastmod>2023-03-04T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2022-32896/</loc><lastmod>2023-03-04T10:37:00+00:00</lastmod></url><url><loc>/post/macos-sandbox-escape-via-terminal/</loc><lastmod>2022-11-18T10:37:00+00:00</lastmod></url><url><loc>/tags/sandbox-escape/</loc><lastmod>2022-11-18T10:37:00+00:00</lastmod></url><url><loc>/tags/security/</loc><lastmod>2022-11-18T10:37:00+00:00</lastmod></url><url><loc>/post/macos-red-teaming-apple-signed-java/</loc><lastmod>2022-07-11T10:37:00+00:00</lastmod></url><url><loc>/post/macos-red-teaming-initial-access-via-applescript-url/</loc><lastmod>2022-03-18T10:37:00+00:00</lastmod></url><url><loc>/post/macos-red-teaming-bypass-tcc-with-old-apps/</loc><lastmod>2022-03-10T10:37:00+00:00</lastmod></url><url><loc>/post/macos-red-teaming-get-ad-credentials-from-nomad/</loc><lastmod>2022-03-03T10:37:00+00:00</lastmod></url><url><loc>/post/bypass-tcc-via-privileged-helpers-aka-cve-2020-10008/</loc><lastmod>2021-12-07T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2020-10008/</loc><lastmod>2021-12-07T10:37:00+00:00</lastmod></url><url><loc>/post/change-home-directory-and-bypass-tcc-aka-cve-2020-27937/</loc><lastmod>2021-09-09T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2020-27937/</loc><lastmod>2021-09-09T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2020-29621/</loc><lastmod>2021-09-02T10:37:00+00:00</lastmod></url><url><loc>/post/play-the-music-and-bypass-tcc-aka-cve-2020-29621/</loc><lastmod>2021-09-02T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2021-30658/</loc><lastmod>2021-06-18T10:37:00+00:00</lastmod></url><url><loc>/tags/gatekeeper/</loc><lastmod>2021-06-18T10:37:00+00:00</lastmod></url><url><loc>/post/m1-macs-gatekeeper-bypass-aka-cve-2021-30658/</loc><lastmod>2021-06-18T10:37:00+00:00</lastmod></url><url><loc>/tags/cve-2021-30655/</loc><lastmod>2021-05-10T13:37:00+00:00</lastmod></url><url><loc>/tags/lpe/</loc><lastmod>2021-05-10T13:37:00+00:00</lastmod></url><url><loc>/post/press-5-keys-and-become-root-aka-cve-2021-30655/</loc><lastmod>2021-05-10T13:37:00+00:00</lastmod></url><url><loc>/tags/firefox/</loc><lastmod>2021-03-09T13:37:00+00:00</lastmod></url><url><loc>/post/how-to-rob-a-firefox/</loc><lastmod>2021-03-09T13:37:00+00:00</lastmod></url><url><loc>/tags/cve-2021-3162/</loc><lastmod>2021-01-21T13:37:00+00:00</lastmod></url><url><loc>/tags/docker/</loc><lastmod>2021-01-21T13:37:00+00:00</lastmod></url><url><loc>/post/when-vulnerable-library-is-actually-your-physical-book/</loc><lastmod>2021-01-21T13:37:00+00:00</lastmod></url><url><loc>/tags/firewall/</loc><lastmod>2020-11-18T13:37:00+00:00</lastmod></url><url><loc>/tags/network-extension/</loc><lastmod>2020-11-18T13:37:00+00:00</lastmod></url><url><loc>/post/network-extension-framework-aka-swiss-cheese/</loc><lastmod>2020-11-18T13:37:00+00:00</lastmod></url><url><loc>/tags/privacy/</loc><lastmod>2020-11-18T13:37:00+00:00</lastmod></url><url><loc>/post/stealing-macos-apps-keychain-entries/</loc><lastmod>2020-10-30T13:37:00+00:00</lastmod></url><url><loc>/tags/exploitation/</loc><lastmod>2020-06-29T13:37:00+00:00</lastmod></url><url><loc>/post/learn-xpc-exploitation-part-3-code-injections/</loc><lastmod>2020-06-29T13:37:00+00:00</lastmod></url><url><loc>/tags/xpc/</loc><lastmod>2020-06-29T13:37:00+00:00</lastmod></url><url><loc>/tags/0day/</loc><lastmod>2020-04-30T00:00:00+00:00</lastmod></url><url><loc>/tags/ios/</loc><lastmod>2020-04-30T00:00:00+00:00</lastmod></url><url><loc>/post/stealing-your-sms-messages-with-ios-0day/</loc><lastmod>2020-04-30T00:00:00+00:00</lastmod></url><url><loc>/post/learn-xpc-exploitation-part-2-say-no-to-the-pid/</loc><lastmod>2020-04-23T13:37:00+00:00</lastmod></url><url><loc>/post/learn-xpc-exploitation-part-1-broken-cryptography/</loc><lastmod>2020-03-28T13:37:00+00:00</lastmod></url><url><loc>/post/abusing-electron-apps-to-bypass-macos-security-controls/</loc><lastmod>2019-12-18T13:37:00+00:00</lastmod></url><url><loc>/tags/app-notarization/</loc><lastmod>2019-08-08T20:13:01+02:00</lastmod></url><url><loc>/post/dangerous-get-task-allow-entitlement/</loc><lastmod>2019-08-08T20:13:01+02:00</lastmod></url><url><loc>/tags/get-task-allow/</loc><lastmod>2019-08-08T20:13:01+02:00</lastmod></url><url><loc>/tags/bear.app/</loc><lastmod>2019-03-02T11:12:10+01:00</lastmod></url><url><loc>/post/stealing-bear-notes-with-url-schemes/</loc><lastmod>2019-03-02T11:12:10+01:00</lastmod></url><url><loc>/tags/url-schemes/</loc><lastmod>2019-03-02T11:12:10+01:00</lastmod></url><url><loc>/post/dissecting-logitech-options-on-macos/</loc><lastmod>2019-01-31T21:21:12+00:00</lastmod></url><url><loc>/categories/</loc><lastmod>2018-12-18T09:23:56+00:00</lastmod></url><url><loc>/categories/macos/</loc><lastmod>2018-12-18T09:23:56+00:00</lastmod></url><url><loc>/categories/privacy/</loc><lastmod>2018-12-18T09:23:56+00:00</lastmod></url><url><loc>/post/sandboxed-malware-can-control-your-pasteboard/</loc><lastmod>2018-12-18T09:23:56+00:00</lastmod></url><url><loc>/newsletter/</loc><lastmod>2018-12-08T21:24:29+00:00</lastmod></url><url><loc>/categories/ios/</loc><lastmod>2018-11-12T23:58:36+00:00</lastmod></url><url><loc>/tags/open-source/</loc><lastmod>2018-11-12T23:58:36+00:00</lastmod></url><url><loc>/categories/open-source/</loc><lastmod>2018-11-12T23:58:36+00:00</lastmod></url><url><loc>/post/your-signal-messages-can-leak-via-locked-screen-on-macos/</loc><lastmod>2018-11-12T23:58:36+00:00</lastmod></url><url><loc>/post/clone-you-finger-bypassing-touchid/</loc><lastmod>2018-08-21T21:42:37+00:00</lastmod></url><url><loc>/tags/fun/</loc><lastmod>2018-08-21T21:42:37+00:00</lastmod></url><url><loc>/categories/fun/</loc><lastmod>2018-08-21T21:42:37+00:00</lastmod></url><url><loc>/tags/conference/</loc><lastmod>2018-07-09T17:23:42+00:00</lastmod></url><url><loc>/categories/conference/</loc><lastmod>2018-07-09T17:23:42+00:00</lastmod></url><url><loc>/post/my-thoughts-after-appsec-eu/</loc><lastmod>2018-07-09T17:23:42+00:00</lastmod></url><url><loc>/post/your-encrypted-photos-in-macos-cache/</loc><lastmod>2018-06-02T13:24:51+00:00</lastmod></url><url><loc>/post/authenticated-rce-in-dasan-routers/</loc><lastmod>2018-04-26T22:38:16+00:00</lastmod></url><url><loc>/categories/rce/</loc><lastmod>2018-04-26T22:38:16+00:00</lastmod></url><url><loc>/tags/routers/</loc><lastmod>2018-04-26T22:38:16+00:00</lastmod></url><url><loc>/categories/routers/</loc><lastmod>2018-04-26T22:38:16+00:00</lastmod></url><url><loc>/categories/vulnerability/</loc><lastmod>2018-04-26T22:38:16+00:00</lastmod></url><url><loc>/post/playing-with-hacker-conf/</loc><lastmod>2018-04-09T10:02:41+00:00</lastmod></url><url><loc>/post/cordova-keychain-leak/</loc><lastmod>2018-03-29T16:48:12+00:00</lastmod></url><url><loc>/post/freeplane-xxe/</loc><lastmod>2018-03-19T23:00:10+00:00</lastmod></url><url><loc>/tags/xxe/</loc><lastmod>2018-03-19T23:00:10+00:00</lastmod></url><url><loc>/categories/xxe/</loc><lastmod>2018-03-19T23:00:10+00:00</lastmod></url></urlset>