
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Varik&#39;s Blog</title>
      <link>https://varik.dev/blog</link>
      <description>Varik&#39;s blog</description>
      <language>en-us</language>
      <managingEditor>varikmatevosyan@gmail.com (Varik Matevosyan)</managingEditor>
      <webMaster>varikmatevosyan@gmail.com (Varik Matevosyan)</webMaster>
      <lastBuildDate>Mon, 27 Jul 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://varik.dev/tags/pac/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://varik.dev/blog/jsc/pois0nsword-native-calls</guid>
    <title>pois0nSword: From Renderer R/W to Native Calls on iOS 26.1</title>
    <link>https://varik.dev/blog/jsc/pois0nsword-native-calls</link>
    <description>Arbitrary read/write is not code execution. This post walks the road from read64/write64 to a real native call inside the WebContent sandbox on iOS 26.1: disabling the GC, parking a thread inside dlopen, making dyld&#39;s own allocator install our interpose table, the three locks in that path which 26.1 now checks in ways 18.6 did not - and the default-false embedder preference that silently disables the phone-number trigger on stock hardware.</description>
    <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
    <author>varikmatevosyan@gmail.com (Varik Matevosyan)</author>
    <category>PWN</category><category>JSC</category><category>JavaScriptCore</category><category>WebKit</category><category>Safari</category><category>iOS</category><category>dyld</category><category>PAC</category><category>Browser Exploitation</category>
  </item>

    </channel>
  </rss>
