Recon 2026

Stefan Esser

Stefan Esser is an independent security researcher focused on Apple platform internals. He is best known for early work on PHP security, including Hardened-PHP and Suhosin, as well as vulnerability research across a wide range of software. Over the last decade his work has centered on iOS and macOS, with a focus on kernel and Apple Silicon security architecture. He co-authored iOS Hackers Handbook and regularly speaks internationally about Apple security research and reverse engineering.


Session

06-20
10:00
60min
Beyond XNU: Anatomy of the Secure Kernel & Exclaves on Apple Silicon
Stefan Esser

Apple’s platform security story is shifting. Security critical functionality is increasingly moving out of the traditional XNU kernel into the guarded world, an Apple Silicon proprietary secure execution mode. Initially used for the Secure Page Table Monitor (SPTM) and the Trusted Execution Monitor (TXM), it now also hosts a separate CL4 microkernel, the Secure Kernel, which runs Exclaves. Exclaves are isolated components that XNU can communicate with through defined interfaces.

This talk is a deep technical tour of the Secure Kernel and the Exclave ecosystem as it exists on modern iOS and macOS. We will build a clear mental model of component roles, privilege separation, IPC patterns, shared memory data flows, and the choke points where validation and policy decisions occur. From there, we will show how to identify endpoints, recover message formats, map memory and permissions, and instrument execution so you can turn black box components into something you can actually audit.

The goal is to leave attendees with concrete strategies for finding vulnerabilities and mitigation bypass opportunities in this new Apple security perimeter.

Grand Salon Opera