Triangulating TrueType Fonts On macOS: Reconstructing CVE-2023-41990

No ratings

Presented at Objective by the Sea 2024 by

When Kaspersky researchers started unraveling, what they dubbed, Operation Triangulation in the fall of 2023, the world was thoroughly impressed by the slew of uncovered vulnerabilities. While memory map and MMIO vulnerabilities garnered the most attention, one part of the chain was mostly glanced over by the public: the initial PDF exploit. Details that were published simply stated that it was a vulnerability in an undocumented TrueType instruction in Apple's font rendering code. With no actual exploit sample to analyze, we set out to rediscover the vulnerability and perform thorough root cause analysis. Reconstructing the proof-of-concept for this vulnerability led to interesting insights into font rendering on macOS and iOS, enabled us to search for variants of this vulnerability and to potentially detect instances of the exploit. Join us in spelunking through some of the oldest code running on the latest iOS and macOS!