{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:46:21Z","timestamp":1787017581920,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":71,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690189","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"64-78","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple Silicon"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4100-9338","authenticated-orcid":false,"given":"Hyerean","family":"Jang","sequence":"first","affiliation":[{"name":"Korea University, Seoul, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1887-7009","authenticated-orcid":false,"given":"Taehun","family":"Kim","sequence":"additional","affiliation":[{"name":"Korea University, Seoul, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4831-7392","authenticated-orcid":false,"given":"Youngjoo","family":"Shin","sequence":"additional","affiliation":[{"name":"Korea University, Seoul, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. M1ssing Register Access Controls Leak EL0 State. https:\/\/m1racles.com\/"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833711"},{"key":"e_1_3_2_1_3_1","unstructured":"Apple. 2021. Kernel extensions in macOS. https:\/\/support.apple.com\/fr-ml\/guide\/security\/sec8e454101b\/web"},{"key":"e_1_3_2_1_4_1","unstructured":"Apple. 2023. xnu\/osfmk\/arm\/arm_init.c. https:\/\/github.com\/apple-oss-distributions\/xnu\/blob\/main\/osfmk\/arm\/arm_init.c"},{"key":"e_1_3_2_1_5_1","unstructured":"Apple. 2023. xnu\/osfmk\/armx86_64\/copyio.c. https:\/\/github.com\/apple-oss-distributions\/xnu\/blob\/main\/osfmk\/x86_64\/copyio.c"},{"key":"e_1_3_2_1_6_1","unstructured":"Apple. 2024. xnu\/bsd\/kern\/syscalls.master. https:\/\/github.com\/apple-oss-distributions\/xnu\/blob\/main\/bsd\/kern\/syscalls.master"},{"key":"e_1_3_2_1_7_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Barberis Enrico","year":"2022","unstructured":"Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano Giuffrida. 2022. Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 Attacks. In 31st USENIX Security Symposium (USENIX Security 22). 971--988."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446708"},{"key":"e_1_3_2_1_9_1","volume-title":"SpecROP: Speculative Exploitation of ROP Chains. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Bhattacharyya Atri","year":"2020","unstructured":"Atri Bhattacharyya, Andr\u00e9s S\u00e1nchez, Esmaeil M. Koruyeh, Nael Abu-Ghazaleh, Chengyu Song, and Mathias Payer. 2020. SpecROP: Speculative Exploitation of ROP Chains. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). 1--16."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363219"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384747"},{"key":"e_1_3_2_1_12_1","volume-title":"KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write Vulnerabilities. In 29th USENIX Security Symposium (USENIX Security 20)","author":"Chen Weiteng","year":"2020","unstructured":"Weiteng Chen, Xiaochen Zou, Guoren Li, and Zhiyun Qian. 2020. KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write Vulnerabilities. In 29th USENIX Security Symposium (USENIX Security 20). 1093--1110."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813671"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485902"},{"key":"e_1_3_2_1_15_1","unstructured":"Apple Developer. 2014. Overview of the Mach-O Executable Format. https:\/\/developer.apple.com\/library\/archive\/documentation\/Performance\/Conceptual\/CodeFootprint\/Article"},{"key":"e_1_3_2_1_16_1","unstructured":"Apple Developer. 2024. Apple Silicon CPU Optimization Guide. https:\/\/developer.apple.com\/documentation\/apple-silicon\/cpu-optimization-guide"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66332-6_11"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417289"},{"key":"e_1_3_2_1_20_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Gras Ben","year":"2018","unstructured":"Ben Gras, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2018. Translation leak-aside buffer: Defeating cache side-channel protections with TLB attacks. In 27th USENIX Security Symposium (USENIX Security 18). 955--972."},{"key":"e_1_3_2_1_21_1","volume-title":"Kernel isolation: From an academic idea to an efficient patch for every computer. ;login: 43, 4","author":"Gruss Daniel","year":"2018","unstructured":"Daniel Gruss, Dave Hansen, and Brendan Gregg. 2018. Kernel isolation: From an academic idea to an efficient patch for every computer. ;login: 43, 4 (2018), 10--14."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62105-0_11"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978356"},{"key":"e_1_3_2_1_24_1","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Gruss Daniel","year":"2015","unstructured":"Daniel Gruss, Raphael Spreitzer, and Stefan Mangard. 2015. Cache template attacks: Automating attacks on inclusive Last-Level caches. In 24th USENIX Security Symposium (USENIX Security 15). 897--912."},{"key":"e_1_3_2_1_25_1","volume-title":"Leaky Address Masking: Exploiting Unmasked Spectre Gadgets with Noncanonical Address Translation. In 2024 IEEE Symposium on Security and Privacy (S&P). IEEE, 158--158","author":"Hertogh Math\u00e9","year":"2024","unstructured":"Math\u00e9 Hertogh, Sander Wiebing, and Cristiano Giuffrida. 2024. Leaky Address Masking: Exploiting Unmasked Spectre Gadgets with Noncanonical Address Translation. In 2024 IEEE Symposium on Security and Privacy (S&P). IEEE, 158--158."},{"key":"e_1_3_2_1_26_1","volume-title":"Branch Different-Spectre Attacks on Apple Silicon. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. 116--135","author":"Hetterich Lorenz","year":"2022","unstructured":"Lorenz Hetterich and Michael Schwarz. 2022. Branch Different-Spectre Attacks on Apple Silicon. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. 116--135."},{"key":"e_1_3_2_1_27_1","volume-title":"18th USENIX security symposium (USENIX Security 09). 383--398.","author":"Hund Ralf","unstructured":"Ralf Hund, Thorsten Holz, and Felix C Freiling. 2009. Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms. In 18th USENIX security symposium (USENIX Security 09). 383--398."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.23"},{"key":"e_1_3_2_1_29_1","unstructured":"Intel. 2024. Intel 64 and IA-32 Architectures Software Developer Manuals. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-sdm.html"},{"key":"e_1_3_2_1_30_1","volume-title":"MicroCFI: Microarchitecture-Level Control-Flow Restrictions for Spectre Mitigation","author":"Jang Hyerean","year":"2023","unstructured":"Hyerean Jang and Youngjoo Shin. 2023. MicroCFI: Microarchitecture-Level Control-Flow Restrictions for Spectre Mitigation. IEEE Access (2023)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978321"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616611"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103437"},{"key":"e_1_3_2_1_34_1","volume-title":"DevIOus: Device-Driven Side-Channel Attacks on the IOMMU. In 2023 IEEE Symposium on Security and Privacy (S&P). IEEE, 2288--2305","author":"Kim Taehun","year":"2023","unstructured":"Taehun Kim, Hyeongjin Park, Seokmin Lee, Seunghee Shin, Junbeom Hur, and Youngjoo Shin. 2023. DevIOus: Device-Driven Side-Channel Attacks on the IOMMU. In 2023 IEEE Symposium on Security and Privacy (S&P). IEEE, 2288--2305."},{"key":"e_1_3_2_1_35_1","volume-title":"ThermalBleed: A Practical Thermal Side-Channel Attack","author":"Kim Taehun","year":"2022","unstructured":"Taehun Kim and Youngjoo Shin. 2022. ThermalBleed: A Practical Thermal Side-Channel Attack. IEEE Access (2022)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3399742"},{"key":"e_1_3_2_1_37_1","volume-title":"12th USENIX Workshop on Offensive Technologies (WOOT 18)","author":"Koruyeh Esmaeil Mohammadian","year":"2018","unstructured":"Esmaeil Mohammadian Koruyeh, Khaled N. Khasawneh, Chengyu Song, and Nael Abu-Ghazaleh. 2018. Spectre Returns! Speculation Attacks using the Return Stack Buffer. In 12th USENIX Workshop on Offensive Technologies (WOOT 18). USENIX Association."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00033"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00027"},{"key":"e_1_3_2_1_40_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Lipp Moritz","year":"2022","unstructured":"Moritz Lipp, Daniel Gruss, and Michael Schwarz. 2022. AMD prefetch attacks through power and time. In 31st USENIX Security Symposium (USENIX Security 22). 643--660."},{"key":"e_1_3_2_1_41_1","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Lipp Moritz","year":"2016","unstructured":"Moritz Lipp, Daniel Gruss, Raphael Spreitzer, Cl\u00e9mentine Maurice, and Stefan Mangard. 2016. ARMageddon: Cache attacks on mobile devices. In 25th USENIX Security Symposium (USENIX Security 16). 549--564."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00063"},{"key":"e_1_3_2_1_43_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In 27th USENIX Security Symposium (USENIX Security 18). 973--990."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3623652.3623669"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243761"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00048"},{"key":"e_1_3_2_1_48_1","unstructured":"Microsoft. 2018. KVA Shadow: Mitigating Meltdown on Windows. https:\/\/msrc.microsoft.com\/blog\/2018\/03\/kva-shadow-mitigating-meltdown-on-windows\/"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3470496.3527429"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"crossref","unstructured":"Ryan Roemer Erik Buchanan Hovav Shacham and Stefan Savage. 2012. Return-Oriented Programming: Systems Languages and Applications. In ACM Transactions on Information and System Security (TISSEC). 1--34.","DOI":"10.1145\/2133375.2133377"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354252"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_3_2_1_53_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Shusterman Anatoly","year":"2021","unstructured":"Anatoly Shusterman, Ayush Agarwal, Sioli O'Connell, Daniel Genkin, Yossi Oren, and Yuval Yarom. 2021. PrimeProbe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses. In 30th USENIX Security Symposium (USENIX Security 21). 2863--2880."},{"key":"e_1_3_2_1_54_1","volume-title":"Robust Website Fingerprinting Through the Cache Occupancy Channel. In 28th USENIX Security Symposium (USENIX Security 19)","author":"Shusterman Anatoly","year":"2019","unstructured":"Anatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser, Prateek Mittal, Yossi Oren, and Yuval Yarom. 2019. Robust Website Fingerprinting Through the Cache Occupancy Channel. In 28th USENIX Security Symposium (USENIX Security 19). 639--656."},{"key":"e_1_3_2_1_55_1","volume-title":"KSG: Augmenting Kernel Fuzzing with System Call Specification Generation. In 2022 USENIX Annual Technical Conference (USENIX ATC 22)","author":"Sun Hao","year":"2022","unstructured":"Hao Sun, Yuheng Shen, Jianzhong Liu, Yiru Xu, and Yu Jiang. 2022. KSG: Augmenting Kernel Fuzzing with System Call Specification Generation. In 2022 USENIX Annual Technical Conference (USENIX ATC 22). 351--366."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_3_2_1_57_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Taneja Hritvik","year":"2023","unstructured":"Hritvik Taneja, Jason Kim, Jie Jeff Xu, Stephan van Schaik, Daniel Genkin, and Yuval Yarom. 2023. Hot Pixels: Frequency, Power, and Temperature Attacks on GPUs and Arm SoCs. In 32nd USENIX Security Symposium (USENIX Security 23). 6275--6292."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833802"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-009-9049-y"},{"key":"e_1_3_2_1_60_1","unstructured":"The UNIX and Linux Forums. 2005. otool(1) [osx man page]. https:\/\/www.unix.com\/man-page\/osx\/1\/otool\/"},{"key":"e_1_3_2_1_61_1","volume-title":"2022 IEEE Symposium on Security and Privacy (S&P). IEEE, 1491--1505","author":"Sanchez Vicarte Jose Rodrigo","year":"2022","unstructured":"Jose Rodrigo Sanchez Vicarte, Michael Flanders, Riccardo Paccagnella, Grant Garrett-Grossman, Adam Morrison, Christopher W Fletcher, and David Kohlbrenner. 2022. Augury: Using data memory-dependent prefetchers to leak data at rest. In 2022 IEEE Symposium on Security and Privacy (S&P). IEEE, 1491--1505."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2953709"},{"key":"e_1_3_2_1_63_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Weber Daniel","year":"2021","unstructured":"Daniel Weber, Ahmad Ibrahim, Hamed Nemati, Michael Schwarz, and Christian Rossow. 2021. Osiris: Automated discovery of microarchitectural side channels. In 30th USENIX Security Symposium (USENIX Security 21). 1415--1432."},{"key":"e_1_3_2_1_64_1","volume-title":"RETBLEED: Arbitrary Speculative Code Execution with Return Instructions. In 31st USENIX Security Symposium (USENIX Security 22)","author":"Wikner Johannes","year":"2022","unstructured":"Johannes Wikner and Kaveh Razavi. 2022. RETBLEED: Arbitrary Speculative Code Execution with Return Instructions. In 31st USENIX Security Symposium (USENIX Security 22). 3825--3842."},{"key":"e_1_3_2_1_65_1","volume-title":"KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel Vulnerabilities. In 28th USENIX Security Symposium (USENIX Security 19)","author":"Wu Wei","year":"2019","unstructured":"Wei Wu, Yueqi Chen, Xinyu Xing, and Wei Zou. 2019. KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel Vulnerabilities. In 28th USENIX Security Symposium (USENIX Security 19). 1187--1204."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28865-9_8"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813637"},{"key":"e_1_3_2_1_68_1","unstructured":"YaoYuan. 2023. XNU kperf\/kpc demo. https:\/\/gist.github.com\/ibireme\/173517c208c7dc333ba962c1f0d67d12"},{"key":"e_1_3_2_1_69_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner. 2014. FLUSHRELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. In 23rd USENIX Security Symposium (USENIX Security 14). 719--732."},{"key":"e_1_3_2_1_70_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Yin Tingting","year":"2023","unstructured":"Tingting Yin, Zicong Gao, Zhenghang Xiao, Zheyu Ma, Min Zheng, and Chao Zhang. 2023. KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting Mitigations. In 32nd USENIX Security Symposium (USENIX Security 23). 5039--5054."},{"key":"e_1_3_2_1_71_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23). 1973","author":"Yu Jiyong","year":"1990","unstructured":"Jiyong Yu, Aishani Dutta, Trent Jaeger, David Kohlbrenner, and Christopher W. Fletcher. 2023. Synchronization Storage Channels (S2C): Timer-less Cache Side-Channel Attacks on the Apple M1 via Hardware Synchronization Instructions. In 32nd USENIX Security Symposium (USENIX Security 23). 1973--1990."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690189","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690189","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T05:56:29Z","timestamp":1755842189000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690189"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":71,"alternative-id":["10.1145\/3658644.3690189","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690189","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}