4 ms·
Stagefright was not a rootable exploit.
by TwoBit 11y ago
Stagefright was not a rootable exploit.
- saurik 11y agoNot alone, but as part of a chain of exploits (which is what most jailbreaks are, and which is what this document expressly asks for), certainly it is: it allows you to get arbitrary code execution on the device, which can be paired with a kernel exploit (something that has been comparatively quite common) to get root. I mean, this same argument can be said about the individual components of JailbreakMe 2.0 and 3.0: the initial exploit in FreeType only just barely got you the ability to run code as Safari within its even-at-the-time relatively restricted sandbox: it was then paired with a kernel exploit to finish the jailbreak. Zimperium actually did a demo on stage at BlackHat of using Stagefright as the vector to push a privilege escalation (probably some old kernel exploit; I think they said, but I don't remember) to the device, and they have also posted a video of that process. https://www.youtube.com/watch?v=PxQc5gOHnKs https://www.youtube.com/watch?v=PxQc5gOHnKs