Vector35 / Vector35/binaryninja-api

RTTI / vtables not discovered in images loaded from dyld shared cache

Open
#6,603 9 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: RTTI Core: Workflow Effort: Low File Format: SharedCache Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Version and Platform (required):

  • Binary Ninja Version: 5.0.7189-dev (79570147)
  • OS: macOS 15.4
  • CPU Architecture: arm64

Bug Description:
RTTI and vtables are discovered and annotated in regular Mach-O binaries, but this does not appear to work in images loaded from the shared cache.

Steps To Reproduce:

  1. Open a macOS 15.x shared cache and load /System/Library/Frameworks/Metal.framework/Versions/A/Metal
  2. Search for typeinfo or vtable in the symbols pane and click around.

Expected Behavior:
Glorious structs!

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the issue by opening a macOS 15.x shared cache and loading /System/Library/Frameworks/Metal.framework/Versions/A/Metal, then search the symbols pane for typeinfo and vtable. Trace the shared-cache image loading and RTTI/vtable discovery paths; done means these symbols are discovered and annotated as they are for regular Mach-O binaries.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
devtools, reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.