Navigating the MTE Landscape: iOS Memory Protection Deep Dive

Atlan Pinabel, Patrick Ventuzelo

OffensiveCon 2026 · Day 1 · Main Stage

This talk, presented by Atlan Pinabel of Fuzzinglabs (with co-author Patrick Ventuzelo), offers a deep dive into **Memory Tagging Extension (MTE)** as implemented within Apple's iOS ecosystem, specifically focusing on its integration into the **XNU kernel** and userland allocators. Titled "Navigating the MTE Landscape," the presentation meticulously unpacks how Apple leverages ARM's hardware-enforced memory corruption mitigation to bolster the security of its operating systems, a strategy Apple refers to as **Memory Integrity Enforcement (MIE)**. The discussion covers the foundational principles of MTE, its practical deployment mechanisms, and the profound implications it holds for both system defenders and offensive security researchers.

AI review

Fuzzinglabs delivers a technically rigorous dissection of Apple's MTE implementation across XNU and libmalloc, going well beyond the ARM architecture docs to map out actual allocator behavior, per-process activation mechanics, and XNU 26.4's policy shifts in concrete detail. No exploit demo and no bypass presented, which caps the ceiling — but the depth of implementation coverage is real work, not a literature survey.

Watch on YouTube