A Remote Pre-Authentication Overflow in LLDB's debugserver
objective-see.org·2h
🧪CBOR Fuzzing
Preview
Report Post

When Good /bins Go Bad

A Remote Pre-Authentication Overflow in LLDB’s debugserver

by: Nathaniel Oh / December 7, 2025

The Objective-See Foundation is supported by:

Note:

In this guest blog post, Nathaniel Oh details a recent bug he discovered and reported to Apple — a remote pre-authentication buffer overflow in LLDB’s debugserver, now patched as CVE-2025-43504.

Mahalo to Nathaniel for sharing his research! 🙏🏽

Introduction

Growing up, I always enjoyed digging through the DVD bins at my local Walmart. I noticed a lot of the same movies were left on top, but if you actually dug in, you’d find more interesting and niche titles.

When a program overflows a buffer, you’re essentially reaching into its bargain bin. Depending …

Similar Posts

Loading similar posts...