This presentation was held at #BSidesBUD2026 IT security conference on 29 April 2026. Short description of the talk: On a cold, sunny autumn day, we sat down with Gergely in a Starbucks to barinstorm a few ideas for vulnerablity research. We quickly found out that we both identified a vulnerability which we both thought was not possible to exploit. While we talked through it, we realized that it might be possible, and that is when our journey started in developing an exploit. We will walk through the entire exploit development process, and how we managed to overcome each obstacle one by one. In our talk we will cover sandbox extensions, XPC calls, reverse XPC calls, ACL inheritance and file system race conditions. This was all needed to gain LPE and escape the sandbox using a vulnerability in osanalyticshelper, which is now identified as CVE-2025-24277. About Csaba Fitzl: I graduated in 2006 as a computer engineer, then worked for 6 years as a network engineer, troubleshooting and designing large networks. Following that, for 8 years I enjoyed being a blue and red teamer focusing on network forensics, malware analysis, adversary simulation, and defense bypasses. I was the lead content developer of the "macOS Exploitation and Penetration Testing" training at OffSec. Currently I'm working for Kandji doing vulnerability research and improving EDR detections. In the last 6 years my primary focus is Apple's macOS and doing Apple vulnerability research as a side hobby. I gave talks and workshops at various international IT security conferences, including Hacktivity, BlackHat, Troopers, SecurityFest, DEFCON, and Objective By The Sea. About Gergely Kálmán: Coder / hacker / freelancer / entrepreneur. I love to break stuff. Currently running my own consultancy firm. https://bsidesbud.com All rights reserved. #bsidesbud2026 #iot #malware