Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

MIE is a combination of enhanced MTE (EMTE) and some highly-overdue software allocator improvements.


It certainly took them a while to introduce MTE! Pixel 8 came out in 2023. I wonder how it compares against hardened_malloc with 48-bit address space and 33-bit ASLR in Graphene. Apple's security team has reported that MIE could break all "known" exploit chains, but so does hardened_malloc. Hard to tell right now which one is best (most def MIE) but everything else included in Graphene is probably making the point moot anyway.


Yes, but it is not MTE, they are technically different. That's what I was attempting to point out but thought it may have been a typo




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: