bellis1000 Profile Banner
Billy Ellis Profile
Billy Ellis

@bellis1000

Followers
22K
Following
21K
Media
3K
Statuses
29K

iOS security researcher

London, England
Joined November 2013
Don't wanna be here? Send us removal request.
@bellis1000
Billy Ellis
9 months
Part 2 of Exploiting the iOS Kernel with PhysPuppet https://t.co/U7Al7Wl5EL
5
38
241
@bellis1000
Billy Ellis
4 days
Spent some time on an old iOS WebKit bug to learn about browser exploitation https://t.co/CDySlTzGM6
5
37
241
@ZygoSec
ZygoSec
4 days
How 1-click iOS exploit chains work (WebKit exploitation basics) https://t.co/ggBkWcFh1d
2
31
140
@tomitokics
Tomi
13 days
My first technical blogpost is out now! Check it out: https://t.co/nIfki9Ym6Q Thanks for the DFF team for their support and to the dfsec people for posting it! Special thanks to @iBSparkes for his assistence :)
@iBSparkes
sparkey
13 days
Our newest @dfsec_com blog post is live, thanks to @tomitokics from @df_forensics for putting this together :-) https://t.co/JoJfTOOXzV
2
26
102
@ZygoSec
ZygoSec
1 month
Does the iPhone 17 Kill Exploitation for Good? (Memory Integrity Enforcement breakdown) https://t.co/CFMl7I7Nlk
0
5
20
@bellis1000
Billy Ellis
1 month
Is the iPhone 17 Safe from Exploitation? (MTE breakdown)
1
14
81
@bellis1000
Billy Ellis
1 month
How Does the iOS Kernel Copy Memory? (Virtual Memory Internals) https://t.co/qdS4mVnmx6
4
43
206
@bellis1000
Billy Ellis
1 month
0
0
3
@bellis1000
Billy Ellis
1 month
How Does the iOS Kernel Copy Memory? (Virtual Memory Internals) https://t.co/qdS4mVnmx6
4
43
206
@b1n4r1b01
binaryboy
2 months
Brief info and POC for this week's Apple 0click iOS 18.6.1 RCE bug CVE-2025-43300 https://t.co/EL3qg56N8X
16
224
795
@alfiecg_dev
Alfie
3 months
Just released a short writeup for the A9 version of the Trigon exploit, which involves getting code execution on a coprocessor before exploiting the kernel - enjoy!
alfiecg.uk
Where did we leave off? Background: KTRR IORVBAR Coprocessors Always-On Processor Investigation AXI? What’s that?! Mapping DRAM Code execution Improving the strategy What about A7 and A8(X)? Conclu...
4
36
174
@bellis1000
Billy Ellis
4 months
Yeah didn’t take long
@app_settings
System Settings
4 months
the difference between beta 1 and beta 3 is CRAZY
0
0
8
@bellis1000
Billy Ellis
4 months
Hiked up a volcano this past weekend. Mad views. 🌋
2
0
31
@dillon_franke
Dillon Franke
4 months
I lightly mentioned CVE-2025-31235, a double-free I found in coreaudiod/CoreAudio, during my OffensiveCon presentation last month. It's been derestricted now, so enjoy my writeup which includes a PoC and dtrace script to help understand the vulnerability!
3
43
200
@bellis1000
Billy Ellis
4 months
Out-of-bounds swap on iOS heap when decoding a malicious audio stream (CVE-2025-31200) https://t.co/qRzR5Qo00T
1
34
193
@bellis1000
Billy Ellis
4 months
How This Weird Exploit Primitive Corrupts iOS Heap Memory
1
38
156
@bellis1000
Billy Ellis
5 months
I think this is the same effect as ‘learn by teaching’ when writing blogs. Fills the gaps in your knowledge.
0
0
6
@bellis1000
Billy Ellis
5 months
When facing a technical challenge, draft a message to a colleague/developer friend. I find that ~50% of the time I figure out the solution before clicking send, just by defining the issue clearly.
2
8
58
@bellis1000
Billy Ellis
5 months
The promo videos for Liquid Glass look beautiful, but seems implementation doesn’t land quite as well. I reckon Apple will partially revert this before full release, making elements more opaque again.
1
0
12
@ProjectZeroBugs
Project Zero Bugs
5 months
Samsung S24: Out of bounds write in VC1 Decoder (svc1d_rr_frm)
0
5
25