EP28 macOS Security Internals: Kernel Exploitation, PAC Defenses, and the Rise of macOS Infostealers with Olivia Gallucci episode artwork

EPISODE · Aug 26, 2026 · 51 MIN

EP28 macOS Security Internals: Kernel Exploitation, PAC Defenses, and the Rise of macOS Infostealers with Olivia Gallucci

from Behind the Binary by Google Cloud Security · host Josh Stroschein

In this episode, we're joined by security researcher Olivia Gallucci to explore macOS low-level security, kernel exploitation, and macOS threat trends. We break down how macOS internals differ from Linux—focusing on IOKit, C++ dynamic class resolution, and Vtable hijacking in kernel drivers. Olivia explains the mechanics behind use-after-free (UAF) vulnerabilities, heap shaping, and legacy kernel exploits, as well as modern Apple hardware and OS defenses like Pointer Authentication Codes (PAC) and kalloc type isolation (PAC IA/DA semantics). We also discuss the evolution of macOS threat research, the rise of macOS info stealers driven by cryptocurrency targeting, local detection telemetry using Endpoint Security (ES) and tools like Mac Monitor, and the current dynamics of vulnerability research and bug bounty programs. Key Discussion Points:Mac vs. Linux Internals: Why macOS isn't "just Linux," and how IOKit’s C++ driver framework creates unique attack surface. Vtable Hijacking & Kernel Exploits: How dynamic method resolution and C++ polymorphism are targeted using UAF, out-of-bounds writes, and heap shaping. Modern Defenses: How Apple leverages Pointer Authentication Codes (PAC IA/DA) and type-isolated heap allocators to disrupt traditional exploit primitives. The Rise of macOS Infostealers: What drove the surge in macOS stealer malware, their simple architecture, and social engineering delivery tactics. Detection & Telemetry: Monitoring local exploit failures, kernel panics, and process events via Endpoint Security (ES Logger) and open-source tools like Mac Monitor. Vulnerability Research Ecosystem: The role of AI in technical research, shifting bug bounty payouts, and the dynamics between vendor programs and third-party research. Resources mentioned:Olivia Gallucci's Blog: oliviagallucci.comMac Monitor by Brandon Dalton: https://github.com/Brandon7CC/mac-monitorJoin the CommunityResearch Hub: Threat research, training events and news:https://cloud.google.com/security/flareThe FLARE Insider: Get community updates and announcements. To subscribe, email [email protected] THE SHOW:Subscribe: Apple Podcasts | Spotify | YouTube

Episode metadata supplied by the publisher feed · Published Aug 26, 2026

Embed this episode

In this episode, we're joined by security researcher Olivia Gallucci to explore macOS low-level security, kernel exploitation, and macOS threat trends. We break down how macOS internals differ from Linux—focusing on IOKit, C++ dynamic class resolution, and Vtable hijacking in kernel drivers. Olivia explains the mechanics behind use-after-free (UAF) vulnerabilities, heap shaping, and legacy kernel exploits, as well as modern Apple hardware and OS defenses like Pointer Authentication Codes (PAC...

Distinct summary based on available episode metadata or transcript content.

Ready to play

EP28 macOS Security Internals: Kernel Exploitation, PAC Defenses, and the Rise of macOS Infostealers with Olivia Gallucci

0:00 51:48

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Behind the Binary by Google Cloud Security?

This episode is 51 minutes long.

When was this Behind the Binary by Google Cloud Security episode published?

This episode was published on August 26, 2026.

Can I download this Behind the Binary by Google Cloud Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!