4 ms·
Honest question, is "execute arbitrary code on the Wi-Fi chip" the same as execute arbitrary code on the SoC (e.g. A10) chip?
by devy 10y ago
Honest question, is "execute arbitrary code on the Wi-Fi chip" the same as execute arbitrary code on the SoC (e.g. A10) chip?
- mikeash 10y agoIt's not identical. The WiFi chip has its own processor running its own code, and that's what the exploit affects. It may be possible, even trivial, to leverage that into running arbitrary code on the main CPU, depending on how the stuff is designed. If the WiFi chip has unrestricted access to RAM then that would be it. If not, it's likely that the OS drivers for the chip aren't hardened against malicious input from the WiFi chip and could be exploited.
- devy 10y ago> If the WiFi chip has unrestricted access to RAM Is this the Wi-Fi chip's own internal memory? Or iPhone's main RAM in SoC?
- delinka 10y agoI'sure mikeash means main RAM, not the wifi internal memory. Given DMA to systm RAM, your device is rooted. Given access to wifi chip's RAM, rooting is probably much harder (but still not impossible.)
- acdha 10y agoApple's been shipping hardware DMA restrictions on Macs for awhile - that first appeared on the security radar in the FireWire era – so it's not inconceivable that it's not as simple as getting DMA access but https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf seems to be silent on that unless I'm missing something.
- mikeash 10y agoIOMMUs are important for external interfaces, but much less so for internal hardware. It's certainly possible that they're doing it here, but I wouldn't bet on it.
- acdha 10y agoIt's gotten a lot of attention on the x86 side for making virtualization safer (e.g. VT-D) but if they're using it they're certainly quiet about it.
- mikeash 10y agoI assume the WiFi chip has its own RAM, but it probably also has access to the main CPU's RAM so it can do DMA: https://en.wikipedia.org/wiki/Direct_memory_access https://en.wikipedia.org/wiki/Direct_memory_access If it has such access, and if that access is unrestricted (both possible and reasonably likely, but not guaranteed) then the WiFi CPU could easily get the main CPU to do whatever it wants.