A race-condition exploit recovers the internal state of XNU's PRNG for IPv6 fragment IDs, enabling off-path fragment spoofing on UDP and TCP protocols.
Cross layer attacks and how to use them (for DNS cache poisoning, device tracking and more).CoRR, abs/2012.07432, 2020
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
One (Thread) Can Keep a (PRNG) Secret, but not Two
A race-condition exploit recovers the internal state of XNU's PRNG for IPv6 fragment IDs, enabling off-path fragment spoofing on UDP and TCP protocols.