Vector35 / Vector35/binaryninja-api

Fixup chains not properly handled in Mach-O view

Open
#7,870 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Version and Platform:

  • Version: Binary Ninja 5.3.8844-dev
  • Edition: Commercial
  • OS: macOS
  • OS Version: Tahoe 26.1 (25B78)
  • CPU Architecture: M2 Pro

Bug Description:

For some iOS binaries, dyld_chained_ptr_64_bind pointers (format DYLD_CHAINED_PTR_64) are not properly handled in fixup chains. These are heavily used in the __got section:

Image

Steps To Reproduce:

  1. Download this example IPA (should work with other ones).
  2. Load the Delta binary it contains with Binary Ninja

Expected Behavior:

Every bind pointer should be bound to its corresponding symbol, by navigating structures of the LC_DYLD_CHAINED_FIXUPS load command.

I suspect symbols are resolved correctly at some point as the following log message appear for every unbound pointer:

[BinaryView.MachoView] Failed to find external symbol "<symbol-name>", couldn't bind symbol at <address>

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by loading the Delta binary from the linked IPA and examining Mach-O handling for the LC_DYLD_CHAINED_FIXUPS load command, especially DYLD_CHAINED_PTR_64 bind pointers in __got. Use the repeated “Failed to find external symbol” log messages to trace the unbound pointers. Done means every bind pointer resolves to its corresponding symbol.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.