Entry Thumbnail

CVE-2025-20678: Mediatek Baseband Unbounded Recursion Leading to Stack Overflow During Handling XML Payload

An attacker sending a malformed SIP message over VoLTE to a device with a Mediatek baseband can trigger the vulnerability described here. This report describes an unbounded recursion issue, which leads to stack overflow. (Note: the issue is stack overflow not stack **buffer** overtflow, i.e. an out-of-bounds write beyond a […]

Posted by
Entry Thumbnail

Quantum readiness: Hybridizing signatures

# Quantum readiness: Hybridizing signatures In light of new legal requirements being enacted in many countries for software providers to adopt hybrid post-quantum cryptography, Synacktiv has initiated research into these novel cryptographic algorithms. After having studied what makes post-quantum cryptography “post-quantum” in the previous articles, we now dissect the concept […]

Posted by
Entry Thumbnail

appledb_rs, a research support tool for Apple platforms

# appledb_rs, a research support tool for Apple platforms Over the years, research on Apple platforms has become significantly more complex, largely due to the numerous countermeasures deployed by the Cupertino company. To address this challenge during our missions on these platforms, we developed appledb_rs: an open-source tool (https://github.com/synacktiv/appledb_rs) that […]

Posted by