SecretCon 2026

Just-In-Time Compilation and JIT Memory Regions on macOS

Olivia Gallucci

Abstract:

Just-In-Time (JIT) compilation is a performance technique that collides with memory safety guarantees, especially Write XOR Execute (W^X) enforcement. macOS hardened this surface over several releases, resulting in a per-thread memory permission model enforced by hardware on Apple Silicon.

This talk explores the evolution of JIT memory management on macOS: the introduction of MAP_JIT, hardened runtime entitlements, and Apple Silicon’s enforcement of W^X through APRR and thread-local permission toggles via pthread_jit_write_protect_np. We’ll discuss how these features map to kernel-enforced page permissions, how PAC and BTI constrain code reuse, and why some exploit primitives (like RWX memory) are less viable within protected regions on Macs.

The session will provide detection opportunities for JIT exploits (Safari, Rosetta 2), and explain how understanding their constraints is great for threat modeling surfaces in macOS processes, detecting anomalous memory transitions, and building hardened JIT engines. We’ll conclude with tooling ideas, guidance for runtime developers, and areas for future detection research.

Olivia Gallucci

Likes neon glow under the desert sky

Olivia Gallucci is a Security Engineer at Datadog focused on macOS internals, and detection engineering. She previously worked in offensive security at Apple, SECUINFRA GmbH, the U.S. Government, and Deloitte. Olivia is also the founder of two ventures: Offensive Services, a security consultancy, and OG Health & Fitness. She graduated top of her class and is passionate about low-level systems, free and open-source software, and security research. Outside of cybersecurity, she enjoys competitive sailing, cooking, and reading about the history of computing.