Hacker News new | ask | show | jobs
by throwaway290 1473 days ago
Perhaps the kext with the overflow may not necessarily look malicious? It can serve as an actually useful kext and pass review.
2 comments

These days all kexts look malicious.
Yeah. The bundled ones in the main OS image are the worst. Who the hell knows what nefarious acts lie behind IOPCIFamily.kext?!

/s, though not entirely, moving more stuff to unprivileged contexts would be nice

yeah but if you can trick the user to do that, you can already trick him to do more