The article demonstrates how attackers can exploit Rosetta 2's translation layer on Apple Silicon to inject and execute malicious x86_64 code. It covers techniques including AOT/JIT manipulation, library swizzling, and function pointer hijacking, with real examples from North Korean malware targeting Rosetta 2-dependent applications.
Background
Rosetta 2 is Apple's binary translation layer that enables x86_64 applications to run on Apple Silicon Macs, combining ahead-of-time and just-in-time compilation. This technique explores a novel attack surface created by Rosetta 2's complex translation pipeline on macOS.
- Source
- Lobsters
- Published
- Aug 20, 2026 at 06:05 AM
- Score
- 8.0 / 10