
Black Hat Talk: Detecting Race Conditions in macOS Due to GCD Misuse
The video presents a Black Hat talk by Olivia Gallucci from Datadog on detecting race conditions in macOS, specifically how misuse of Grand Central Dispatch (GCD) leads to vulnerabilities in privileged system services. It explains GCD’s role as Apple’s concurrency framework, detailing how misconfigured dispatch queues—serial vs. concurrent—and Quality of Service (QoS) classes can cause race conditions, priority inversions, and deadlocks. The talk highlights a 2018 CVE in the com.apple.gsscred XPC service, where a missing target queue configuration enabled a use-after-free race condition, allowing unprivileged processes to execute arbitrary code in a root context. Key tools mentioned include Xcode’s Thread Performance Checker for runtime detection of priority inversions and static review patterns for unsafe queuing in XPC services. The presentation also covers symptoms like thread churn, CPU spikes, and crash patterns in telemetry as indicators of concurrency flaws. Apple’s abandoned Security Transforms API in macOS 10.7 is cited as an example of unconstrained concurrency causing system instability. The talk concludes that architectural assumptions about serialization in privileged code are security-relevant and require proactive detection.