VLDB 2026 Research / reviewers in the wild / expert
Jiaxun Zhu
dblp:353/7626
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0005-4288-4590ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Demystifying the Access Control Mechanism of ESXi VMKernel
Zexiang Zhang, Jiaxun Zhu, Jiaqing Huang, Wenbo Shen, Yuliang Lu, Min Zhang 0054, Zulie Pan |
NDSS | 3 |
| 2026 | Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux SystemsabstractThe widespread deployment of control-flow integrity has shifted attackers' focus to non-control data attacks. In OS kernel exploits, attackers can gain root access or escalate privileges by corrupting critical non-control objects without hijacking the control flow. However, searching for exploitable non-control data in the OS kernel is challenging because of the data's semantic complexity and lack of universal patterns. This work represents the first study to semi-automatically discover and evaluate exploitable non-control data within the Linux kernel's file system, with minimal domain knowledge. Utilizing a custom analysis and testing framework, we identify promising candidate objects both statically and dynamically. We categorize these objects into types suitable for various exploit strategies, including a systematic strategy to overcome defenses that isolate many of these objects. These objects can be exploitable without requiring KASLR, thus making the exploits simpler and more reliable. We evaluate the exploitability of the file system objects using 18 real-world CVEs with various exploit strategies. We further develop 10 end-to-end exploits against the kernel with all state-of-the-art mitigations enabled. Jinmeng Zhou, Ziyue Pan, Jiayi Hu, Jiaxun Zhu, Wenbo Shen, Guoren Li, Zhiyun Qian |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | M1Pecker: A Dynamic Analysis Framework for Pointer Authentication in Apple M1 ChipsabstractPointer Authentication (PA) was introduced by ARMv8.3 to safeguard the integrity of pointers. While ARM specification allows vendors to implement and customize PA, Apple has tailored it to protect iPhones and Macs with M-series chips on their hardware. Since its debut, Apple PA has been considered to introduce domain isolation to defeat pointer corruption. However, its details have not been publicly disclosed. To shed light on Apple PA customization, this paper first establishes a security model for PA that defines expected properties for cross-domain and intra-domain isolation. We then introduce M1Pecker, a novel analysis framework built upon our Trap-Relay-Based Automated Analysis technique, to evaluate Apple's hardware and software dynamically and automatically against this model. Based on our framework, we perform a comprehensive kernel analysis that combines static and dynamic approaches. We confirm that Apple PA employs multiple diversifiers that robustly satisfy our model's cross-domain isolation property. In contrast, our intra-domain analysis of the XNU kernel identifies violations of intra-domain properties, resulting in four attack surfaces. Apple has fixed these issues in a security update, assigned us a new CVE, and publicly acknowledged our findings. Jiaxun Zhu, Zechao Cai, Wenbo Shen, Yutian Yang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Chekhov's Gun: Uncovering Hidden Risks in macOS Application-Sandboxed PID-Domain ServicesabstractmacOS delegates many high-privilege operations to dedicated PID-domain services, which applications can register and communicate with through inter-process communication (IPC). This architecture improves userland stability and security but also introduces attractive attack surfaces for adversaries. In this paper, we systematically analyze PID-domain services and uncover an overlooked attack vector: PID-domain services that are restricted to an Application Sandbox identical to the calling application can still be exploited due to subtle entitlement differences. Minghao Lin, Jiaxun Zhu, Tingting Yin, Zechao Cai, Guanxing Wen, Yanan Guo 0002, Mengyuan Li 0004 |
CCS | 2 |
| 2024 | CrossFire: Fuzzing macOS Cross-XPU Memory on Apple SiliconabstractModern computing systems increasingly utilize XPUs, such as GPUs and NPUs, for specialized computation tasks.While these XPUs provide critical functionalities, their security protections are generally weaker than those of CPUs, making them attractive attack targets.In particular, Apple silicon optimizes memory usage by adopting a unified memory architecture (UMA), which employs shared memory regions (termed cross-XPU memory) to facilitate communication between CPUs and XPUs.Although the cross-XPU memory enhances performance, it also introduces a new attack surface.Unfortunately, the difficulty in identifying effective shared memory regions and generating valid payloads makes fuzzing cross-XPU memory a challenging problem that cannot be resolved effectively by existing fuzzing techniques.Therefore, we propose CrossFire, the first fuzzer targeting Apple silicon XPU by fuzzing cross-XPU memory, to evaluate this new attack surface.Initially, we conduct an in-depth cross-XPU memory analysis to investigate the challenges of fuzzing XPU.To address these challenges, CrossFire introduces two novel techniques to pinpoint effective fuzzing regions in cross-XPU memory and trace kernel execution information to extract data constraints.Leveraging these techniques, we develop CrossFire based on the m1n1 hypervisor to monitor cross-XPU memory accesses and perform grey-box hooking-based fuzzing.We further evaluate CrossFire on macOS Ventura, where it has identified 15 new zero-day bugs, 8 of which have been confirmed by Apple. Jiaxun Zhu, Minghao Lin, Tingting Yin, Zechao Cai, Yu Wang 0229, Wenbo Shen |
CCS | 1 |
| 2023 | Demystifying Pointer Authentication on Apple M1
Zechao Cai, Jiaxun Zhu, Wenbo Shen, Yutian Yang, Jinku Li, Kui Ren 0001 |
USENIX Security Symposium | 2 |