latest iOS 18.4 has brought to light a significant bug that affects dynamic symbol parsing on devices that support Pointer Authentication Code (PAC).
See also: iOS 18.4 – Apple Intelligence: How to enable Priority Notifications?

This issue, first observed by Fabien Perigaud, a well-known reverse engineering expert, has implications for applications that rely on dynamic library loading and symbol analysis.
The bug occurs when applications attempt to resolve symbols using the dynamic dlsym(), particularly on devices featuring the A15 SoC, such as the iPhone SE .
The bug occurs due to an omission in the implementation of dlsym() within dyld in iOS 18.4, where certain symbols, such as strcmp , are incorrectly signed or unsigned, resulting in applications crashing
When an application uses the dlsym() function to resolve symbols such as strcmp, which are re-exported from libsystem_platform.dylib with a special flag (EXPORT_SYMBOL_FLAGS_STUB_AND_RESOLVER), the function pointer returned should have the PAC signature removed before being converted to an offset.
However, in iOS 18.4, this removal is not performed, resulting in the pointer being signed twice. This double signing leads to either an invalid signature or an unsigned pointer, causing the app to crash due to a kernel protection failure.
See also: iOS 18.4 update caused problems with CarPlay
Perigaud's research from Synacktiv revealed that the problem stems from the absence of the XPACI in the dyld code, which is responsible for removing the PAC signature from the pointer returned by the resolver function.

This command was present in the previous version, iOS 18.3.2, but its absence in iOS 18.4 leads to the observed behavior. Further experiments confirmed that the pointer was treated as a kernel pointer during the second signing process, which is against the ARMv8.6-A architecture.
This misinterpretation results in the index being signed with all the upper bits set to 1, which, when broken down with the original index, invalidates the first signature or produces an incorrect one.
This bug has significant consequences for developers, particularly those working on applications that dynamically load libraries or use system functions via dlsym().
See also: iOS 18.4 brings Apple Maps upgrade to iPhone
While not all applications crash due to this issue, those that do experience serious stability issues. Developers have found workarounds by manually removing and re-signing the pointers, but this is not a sustainable solution.
Source: cybersecuritynews
