EX-ARRR: Sailing the 0-click Seas
Summary
The article details a zero-click heap overflow in Apple's EXR image decoder (libAppleEXR) that can reach a privileged daemon via iMessage attachments. It covers the discovery process using LLM-guided fuzzing, reproduction on real devices, cross-platform impact, mitigations such as memory tagging and PAC, and practical guidance for defenders and bug hunters.