Credits
Offset finder: Sem Voigtländer
UI: iSn0w
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
dlsym:
0x18084ef90
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
aslr slide (ignore this):
0x140c000
JavaScriptCore base:
0x187a6d000
ModelIO base:
0xfffffffffebf4000
CoreAudio base:
0x183fc3000
disablePrimitiveGigacage:
0x18854aa90
g_gigacageBasePtrs:
0x1b1d58000
g_typedArrayPoisons:
0x1b3311728
startOfFixedExecutableMemoryPool:
0x1b33110b8
endOfFixedExecutableMemoryPool:
0x1b33110c0
jitWriteSeparateHeapsFunction:
0x1b33110c8
useFastPermisionsJITCopy:
0x1b1d54018
ptr_stack_check_guard:
0x1b326bef8
longjmp:
0x180b12778
callbacks:
0x1b33116a0
Sent from my iPhone