Kuboid
Open Luck·Kuboid.in
Security BSides2025
Open in YouTube ↗

MacOS DYLD_LIBRARIES Injection

BSides Mumbai131 views47:53about 1 year ago

This talk demonstrates the technique of dynamic library (dylib) injection on macOS by leveraging the DYLD_INSERT_LIBRARIES environment variable. The speakers explain how the macOS dynamic linker (dyld) processes library loading and how security features like System Integrity Protection (SIP) and Apple Mobile File Integrity (AMFI) attempt to mitigate such attacks. The presentation includes a practical demonstration of bypassing these protections on non-hardened binaries and discusses the impact of code signing and restricted segments on the success of the injection.

Premium Security Audit

We break your app before they do.

Professional penetration testing and vulnerability assessments by the Kuboid Secure Layer team. Securing your infrastructure at every layer.

Get in Touch
Official Security Partner
kuboid.in