3 ms·
Anyone know if the WiFi exploit opened the door to arbitrary code execution on the main CPU?
by CodeWriter23 9y ago
Anyone know if the WiFi exploit opened the door to arbitrary code execution on the main CPU?
- inertial 9y agoIf you are referring to broadpwn aka CVE-2017-9417 [1], it has been fixed (last item in [2]). [1] https://news.ycombinator.com/item?id=14727400 https://news.ycombinator.com/item?id=14727400 [2] https://support.apple.com/en-us/HT207923 https://support.apple.com/en-us/HT207923 Summary : Impact: An attacker within range may be able to execute arbitrary code on the Wi-Fi chip Description: A memory corruption issue was addressed with improved memory handling.
- CodeWriter23 9y agoThis is what I'm interested in, and I saw that Apple fixed the exploit enabling attackers to own the WiFi chip. What I want to know, does owning the WiFi chip on machines not having the patch provide a beachhead to exploiting the iOS kernel. And if so, are there known active exploits at that level?
- stock_toaster 9y agoWasn't there another remote buffer overrun vuln in broadcom's wi-fi chips reported back in april too? yikes... EDIT: found it[1] [1]: https://www.theregister.co.uk/2017/04/05/broadcom_wifi_chip_bugs/ https://www.theregister.co.uk/2017/04/05/broadcom_wifi_chip_...