The article explores the process of reverse engineering Apple's iWork software, detailing the techniques and tools used to analyze its functionality. It discusses the challenges faced during the reverse engineering process and the insights gained about the software's design and architecture. The author aims to provide a deeper understanding of how iWork operates behind the scenes.
Apple released a security patch for CVE-2025-43300, addressing an out-of-bounds write vulnerability in the ImageIO framework that could be exploited in zero-click attacks. The article provides a detailed root cause analysis of the vulnerability and the changes made in the patch, focusing on the modifications in the RawCamera file and the implications for image processing. Researchers have previously explored the vulnerability, revealing its connections to JPEG Lossless compression in DNG files.