INTEL_REPORT
Google Project Zero · published 1/29/2026, 11:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-free vulnerability (CVE-2025-31235) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process o…
https://projectzero.google/2026/01/sound-barrier-2.html
sha256:d9f9b5798b94544f81bcd8c07ef39490eefd733866a3b3fd5d2546c31366b4bb
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| CVE-2025-31235 |
| Open → |