My services

Offensive security on Apple platforms (iOS & macOS).

Application audit

iOS & macOS application security audit

Black-box or grey-box analysis of your application: binary reverse engineering, local storage and keychain, network communications and pinning, IPC and XPC surfaces, anti-tampering and anti-debug protections. The goal is not to produce a compliance checklist, but the attack scenarios a real adversary would take.

Deliverable — detailed report, reproducible attack chains, prioritised recommendations, technical debrief and retest once fixes are in.
Typical duration — 5 to 15 days depending on scope.

Native SDK audit

Third-party SDK and native component audit

A payment, DRM, anti-fraud or MDM SDK embedded in your application inherits all of its privileges, without you ever seeing its source code. Analysis of the shipped binary — dylib, framework or XCFramework, ARM64e included — to establish what it actually collects, what it exposes, and the risk it transfers to your product.

Deliverable — map of the component's real behaviour, gaps against the vendor's documentation, assessment of the residual risk.
Typical duration — 5 to 10 days per component.

Third-party application assessment

Third-party application assessment

Deploying an application across an iOS fleet means knowing precisely what it does. Decision-oriented black-box analysis: data actually collected and where it is sent, permissions and entitlements requested, embedded third-party dependencies, robustness of authentication and encryption mechanisms.

Deliverable — a reasoned opinion a CISO can act on, backed by technical evidence, repeatable at each major release.
Typical duration — 3 to 8 days per application.

Vulnerability research

Vulnerability research and tooling

Part of my time remains dedicated to research on Apple's own systems, under the Security Bug Bounty: in-depth binary analysis, fuzzing campaigns, dynamic instrumentation, and the development of the tooling that work demands — static analysis of IPSW files, Mach-O binary tracing, IDA Pro extensions.

30+ Apple CVEs identified to date, across macOS, iOS, watchOS and visionOS (see the list). This research is what feeds the services above: the techniques applied to your applications are the ones that find flaws in the operating system itself. Tooling built along the way can be adapted to your own teams' needs.

Support with development and remediation on iOS & macOS remains available as a follow-on to an audit.

Discuss your needs