4 ms·
iMessage uses the WebKit rendering engine to run Javascript. The WebKit engine will be patched by its vendor Apple.
by Pilfer 9y ago
iMessage uses the WebKit rendering engine to run Javascript. The WebKit engine will be patched by its vendor Apple.
- ZenoArrow 9y agoUnless I'm missing something, Spectre isn't really a JS-based vulnerability. As far as I know, any code that runs directly on a computer with one of the affected CPUs could be used to perform the Spectre attack. Feel free to correct me if I'm wrong.
- barrkel 9y agoThere are two components: the branch prediction needs to be trained (to get it to speculatively execute the right instructions on context switch to the victim process) and precise timing needs to be available (to exfiltrate data using differences in what got cached). Without executing code, it's difficult to see how the two components could be triggered. Loading complex file formats is structurally similar to interpreting code; the output of the interpretation is some data structure, rather than some side effect, but otherwise it's very similar. There may be some loaders that are controllable and configurable enough to be programmed by data - perhaps something in the video decoding space that isn't offloaded to dedicated hardware or GPU - but I think it would be tough to find. JS or a downloadable game (which already lets people in the front door) of some kind are the best vectors.
- ZenoArrow 9y agoSure, JS was the most obvious attack vector, but my point was that it's not limited to JS. Any code that runs natively on an affected computer can exploit it. The only advantage JS has is that it's easier to get targets to run malicious code through a web browser. You seem to be in agreement with me on this.
- et-al 9y agoUgh.. when Apple introduced apps and stickers into iMessage, I knew it could be a vector for attacks. Too bad Apple doesn't give users the option to have only "text-only" messages.
- dogma1138 9y agoIt does it’s called using SMS.