Comment by AceJohnny2
3 years ago
> There is a vulnerability in the SoCs that I discovered and reported where cache snooping bypasses CTRR at the AMCC level. You can "write" to read only memory ranges and, as long as those writes remain in snoopable cache, they are effective even though AMCC will block them and panic when they are written back. I didn't get any money for that one because the way I exploited it didn't apply to normal macOS (I used it to patch DCP code from m1n1), but now a nation state figured out how to use it for a real exploit chain. "Whoops".
Oooff
Is this like "micro-code patchable" or hard no?
If it's the cache hardware, probably not. That's not programmable, you get whatever configuration the designers baked in, and that's it. Though as described you could likely work around this by changing the cache mode to write-through, albeit at a fairly severe performance penalty for the affected accesses.
Apple supports locking down MSR registers for the CPU's.
I would not be surprised if they added the same functionality to the GPU registers.
There are a tremendous number of debug registers in these things.
Apple has >1000 apple-specific MSR's for the CPUs, mostly used for debugging/testing
However, unlike the GPU, they are protected by more than just PPL. But you can use them from m1n1/etc and see what they do.
It is not surprising to find they have the same for GPU processor, the difference is that the GPU has no IOMMU, so forgetting to map a page that contains the register shadows is exploitable in a way that it's not for the CPU
1 reply →
So it probably also affects Android phones and SBC like RaspberryPi's?
No, this is all Apple hardware. Other SOCs often have equivalent features and might plausibly make the same mistake (which per the Hector Martin toot is effectively "the write back cache doesn't check security access control so you can stuff data into it to be snooped by other devices"). But this bug is Apple-only.
This only works at all because there is no IOMMU for the GPU. So they'd also have to decide not to do that as well.
1 reply →
[dead]
The bypass is Apple-specific… which it must be, because the security feature being bypassed, CTRR, is itself Apple-specific. I don’t think Android phones or Raspberry Pi even have any equivalent.