9 ms·
'Text bomb' is latest Apple bug
- alwillis 9y agoFixed in the latest beta: https://www.macrumors.com/2018/01/17/apple-seeds-ios-11-2-5-beta-6-to-developers/ https://www.macrumors.com/2018/01/17/apple-seeds-ios-11-2-5-...
- gondo 9y agoand yet again they don't care about older iOS versions for people who don't want to brick their phones with updates
- madeofpalk 9y agoHow do you update software without updating it? I'm literally at a loss with how you would like them to resolve it if you don't want to install updates.
- amiga-workbench 9y agoI assume he means backporting bugfixes to previous major releases.
- danso 9y agoYeah I still haven't updated one of my iOS devices because quite a few good apps haven't been updated to be compatible with iOS 11
- ClassyJacket 9y agoI think what they're getting at it, release an iOS 10.3.4 or whatever so that people who don't want iOS 11 can still avoid this bug. They did this once before, around iOS 6 I believe, when the security certificate for Facetime ran out. And it's understandable. iOS 11 made my iPhone 7 - the newest one at the time - so unusable I sold it and got a different phone. It went from a good, snappy phone, to a slow mess that took seconds more to open or switch apps, crashed all the time, had UI glitches all over the place, and was so slow it couldn't play locally downloaded audio without stuttering and slowing down. Ew.
- brokenmachine 9y agoThis really shits me about updates to phones and other devices like my TV. I always cringe a bit when there's an update because the companies never provide any way to downgrade if you're not happy after. It's not only Apple responsible, I wish there was some kind of consumer protections. There should always be a way for a consumer to get a product back to the state is was at the time of purchase.
- BaconJuice 9y agoI'm really curious to know how you think they can possibly do that without you having to update your phone. Care to explain?
- gondo 9y agosee @ClassyJacket response basically release ios 10.3.4
- jdlyga 9y agoSounds like AOL punters. Fate X anyone?
- NedIsakoff 9y agoAnyone have the clode?
- steveadoo 9y agoHere's an archived version: http://web.archive.org/web/20180117063656/https://iabem97.github.io/chaiOS http://web.archive.org/web/20180117063656/https://iabem97.gi...
- Kikawala 9y agohttps://mega.nz/#!X4piUYwA!zXH1vCliaO00V2v2554vegCnXzQ69jdAXS5sUMmyFvU https://mega.nz/#!X4piUYwA!zXH1vCliaO00V2v2554vegCnXzQ69jdAX... 11.7MB HTML file. It crashes the tab in Chrome 65.0.3324.2 64-bit and locks up Firefox 58.0 64-bit on Windows for me.
- 68c12c16 9y agoa mirror of the page could be found here... view-source:https://web.archive.org/web/20180117063656/https://iabem97.github.io/chaiOS/ google chrome browser seems to have disabled the display of the content but other browsers may still be fine with it...
- 68c12c16 9y agoif viewed in a hex editor, this same block of patterns repeated over and over again...seemingly to be an effort to overrun the buffer.... 0x00007B90: A5CCBACD 8774CCB4 CD81CC8D CC92CD8C .....t.......... 0x00007BA0: CD84CC86 CC8FCD8B CD97CD86 CC9BCC8F ................ 0x00007BB0: CC8ECC95 CC87CC82 CC94CC9B CC92CC92 ................ 0x00007BC0: CC86CD91 CD9BCC86 CC8ECCBD CC84CC8B ................ 0x00007BD0: CC91CC88 CD9DCC81 CD81CC81 CC84CCBE ................ 0x00007BE0: CC85CCBE CC86CC84 CD82CC86 CD9DCC89 ................ 0x00007BF0: CC85CC87 CD8CCD9D CC81CC88 CCBFCC9A ................ 0x00007C00: CC82CC86 CD8CCC90 CD9DCC82 CC9ACC80 ................ 0x00007C10: CC93CC9B CD84CC89 CD82CD8A CCBECD8B ................ 0x00007C20: CDA0CC83 CC8ACC8E CD98CC89 CD97CC80 ................ 0x00007C30: CD80CC8A CC8FCDA0 CC80CC80 CD84CD80 ................ 0x00007C40: CD8CCD92 CD92CD91 CC90CD98 CC83CC88 ................ 0x00007C50: CD84CD9B CCBDCD9B CC84CC8D CDA0CC8C ................ 0x00007C60: CC81CD97 CD8BCD86 CD9BCD91 CC8ECCAA ................ 0x00007C70: CCA7CD87 CD95CCB1 CCA8CCBC CD9CCCA6 ................ 0x00007C80: CCA6CC9D CCAFCCAA CC97CCA0 CC9ECD85 ................ 0x00007C90: CCAACCA4 CCB2CCAB CD8ECCAB CD89CD8D ................ 0x00007CA0: CCA2CCA8 CCAACC97 CCACCCA3 CCBACD93 ................ 0x00007CB0: CC9ECCA9 CD87CCA8 CD96CCAF CCBACCA7 ................ 0x00007CC0: CCB1CCBB CCA3CCAE CCABCCA7 CD96CCBA ................ 0x00007CD0: CCAFCCA9 CCA0CCB2 CC96CD95 CCAACCAD ................ 0x00007CE0: CD9ACCA8 CCB9CCB9 CCB0CCA0 CD88CCBA ................ 0x00007CF0: CCA9CD9C CCA3CCA1 CCA0CD8D CC98CCA1 ................ 0x00007D00: CCAFCCA1 CC9DCD87 CCA6CC9D CCBACCBA ................ 0x00007D10: CCAACD9A CCBACD8D CD88CD93 CCB1CCBC ................ 0x00007D20: CCA1CCB1 CCB3CCA4 CD9ACCB0 CCA9CCB2 ................ 0x00007D30: CC9DCCAC CCADCCB9 CC9ECD89 CD89CD9C ................ 0x00007D40: CCA5CCA8 CC9DCD89 CCBACCA2 CC9CCC9F ................ 0x00007D50: CCA5CCBA CD8774CC B4CD81CC 8DCC92CD ......t......... The author comment at the top of the page says, <!-- hello, this was written by Abraham Masri @cheesecakeufo --> <!-- I discovered this bug in like 10 minutes --> If the entire code in the page was whipped up in 10 minutes, then a large part might well be some repetitive copy-paste of a core part...Not exactly sure what this core part does...but given the obvious lack of printable ascii characters (code is way above '0x7F' ), it looks that it could be some unicode type of thing, which then is a bit reminiscing of an old iOS bug back in 2015, as described at this link, https://www.reddit.com/r/iphone/comments/37eaxs/um_can_someone_explain_this_phenomenon/ https://www.reddit.com/r/iphone/comments/37eaxs/um_can_someo... also notice the high frequency of 0xCC and 0xCD throughout the code, which are respectively Breakpoint and INT on x86 architecture -- with its 0xCD's always followed by a single byte whose value is less than 0xA0 -- possibly x86 was used as author's development platform...
- platz 9y agoApple products don't have malware
- devit 9y agoBased on a web search, https://bogdanz.me/work/diddu.html https://bogdanz.me/work/diddu.html might be a working mirror of the proof of concept. It appears to contain a 10MB long UTF-8 mess in both the og:title meta content and in a mailto: link. I'd guess it's supposed to crash iOS apps by either posting that link if it displays links in a thumbnail element using og:title or otherwise by pasting the huge mailto link contained in the webpage, or perhaps only the e-mail address.
- netsharc 9y agoHah. View-Source takes forever to load (in Vivaldi). Wget says it's a 20 MB file. Opening it in Joe in Cygwin kills the Cygwin process. Neat. Also the href attribute inside the <link rel="apple-touch-icon"> points to a HTML URL, but that returns a 404...
- lawlessone 9y agoCould someone just use some sort of fuzzing software to generate these? Just keep trying many until one hits.
- UncleMeat 9y agoYou can, but the number of possible inputs is huge and fuzzing won't prove that no such input exists.
- hamandcheese 9y agoCan confirm, just crashed my friends iPhone X. Required a hard reboot, was locked up completely.
- deleted 9y ago[deleted]
- bzadoroz 9y agoCan confirm - am the owner of the mirror
- 9y ago
- SurrealSoul 9y agoThere was an issue a few years ago where you could send a UTF-8 code to crash whatever app was currently open on an iPhone. I guess this might be the same issue but slightly different?
- menacingly 9y agoThe linked blog assures people that this can't be used to access data. Once something is crashing an app/OS, can you really say that? I mean, can you be sure there's no one clever enough to capitalize on the underlying software error leading to this state?
- 1123581321 9y agoThat would be a general issue with app crashing, and a huge deal worth it’s own series of articles. iOS’ sandboxing makes it so unlikely this exists, it’s not worth mentioning and the sensational writing might be counterproductive to getting the actual issue fixed. To use an analogy, it’d be like mentioning that someone could hack Google in an article about Gmail downtime.
- menacingly 9y agoI see your point, but I actually think users should be _more_ alarmed when an input makes software crash, for just this reason. They tend to think of it as a harmless annoyance. Also, while sandboxing may be designed to prevent this, Messages is probably also designed not to crash on link sharing.
- qubex 9y agoThere's far more risk in software not crashing when it gets malformed or otherwise unexpected input. If an application crashes, it's memory space has been relinquished and its execution process aborted. Yes, something could've been spawned, but... in general crashing when something unexpected comes up is more sensible, desirable behaviour. (Or am I wrong? I'm not a professional programmer. I'm just reasoning from common sense.)
- AgentME 9y agoThe bug causing this crash might be exploitable. Think of a classic buffer overflow: if you overflow a buffer with all zeroes or random data, then the return address most likely gets overwritten with garbage that doesn't point to valid code or a mapped address and the process crashes. But if the attacker specially chose the data they put in the buffer, then they could choose to overwrite the return address with a valid memory address and make the process execute the attacker's own code. If software written in C/C++ crashes and it's not because of a null pointer dereference specifically, then it's realistic to worry about whether it might be because of an exploitable bug (like a buffer overflow, a double-free, etc). One common way for people to try to find exploitable bugs is to script a program to re-run with random input data to figure out which inputs crash it, and then they debug the crashes to see if they're caused by exploitable bugs.
- herodotus 9y agoSo shipping software has an obscure bug that can cause a crash. Why is this news?
- lisper 9y agoBecause Apple once prided itself as a company that made computers that "just worked".
- Bitcoin_McPonzi 9y agoBecause this is completely passive -- you don't have to click on anything or do anything -- this is news. Stop being an apologist for your favorite company.
- mixmastamyk 9y agoTheir lock screen crashing bug from iOS 11 that was fixed with 11.1 came back with 11.2 and I want to throw the thing out the window. Every time I hit the power button it crashes and have to type out the pin.
- menacingly 9y agoI still have the issue where if I access the camera from the lock screen it randomly renders my phone unlockable
- hotpxl 9y ago- Mr Masri said he "always reports bugs" before releasing them. Well I don't think Apple really reads bug reports.
- FPGAhacker 9y agoThey do if you file them at radar.apple.com. I've had back and forths with them on some video card performance issues after sleep after filing a report there.
- Someone1234 9y agoWhat is that site? I have a working Apple ID and it won't even let me sign in.
- haikuginger 9y agoYou have to have a (free) developer account.
- teej 9y agoRadar is Apple’s internal bug tracking system. Outsiders have limited access to it. I believe bugreport.apple.com is the path for submitting bugs as an external developer.
- madeofpalk 9y agoDo any outsiders have access to radar itself? As a developer, when I log into radar.apple.com I'm redirected to bugreport.apple.com
- hotpxl 9y agoI'll try resubmit my bug here and see how it goes. thanks!
- osteele 9y agohttps://support.apple.com/en-us/HT201220 https://support.apple.com/en-us/HT201220 has a section for “Security and privacy researchers”. The process is to send mail to product-security@apple.com, optionally encrypted by Apple Product Security's PGP key. A developer account is not required. Since this page is the top search engine hit for several obvious searches (for example “report apple security vulnerability”), hopefully Mr Masri reported it there.
- Orangeair 9y agoCome to think of it, I believe I've heard of multiple "making the device render this text causes a crash" bugs for Apple devices, but never on any other platforms. Is this type of bug just that much more common on Apple devices, or are there plenty of other cases out there that I just don't know about?
- Kikawala 9y agoNot just simple text, it's UTF-8. Rendering these UTF-8 "text bombs" seems to DoS several applications. This particular one crashes the messages app in iOS, crashes the tab in Chrome, and locks up FireFox. It also crashes several text editors which support UTF-8. Opens quickly in notepad, but takes several minutes in wordpad and it very laggy when scrolling.
- deleted 9y ago[deleted]
- kevin_thibedeau 9y ago> crashes the tab in Chrome, and locks up FireFox Both of which are WebKit wrappers on iOS.
- pwinnski 9y agoReferences to WordPad and notepad suggest they were not running Chrome or Firefox on iOS.
- dspillett 9y ago> but never on any other platforms There have been numerous crash-bugs for the Windows font renderer, and even security exploits using it (especially before windows 10, as earlier than that font rendering was performed in the kernel's space rather than user-land). I wouldn't be surprised to learn of issues (at least of the falling over variety) in common Linux rendering engines and for other OSs too.
- deleted 9y ago
- jakobegger 9y agoSo a crashing bug in the text rendering framework is now worth an article in major publications? I stumbled over two or three of them in the last couple of years while debugging crash reports sent in by customers. Seems that text rendering is hard. Maybe fuzzing CoreText would be a worthwhile target to discover vulnerabilities?
- Someone1234 9y agoOr take text rendering out of the kernel. The whole device shouldn't restart due to malformed text, that's just sloppy. If Microsoft can do it with Windows then Apple can do it on iOS.
- valleyer 9y agoText rendering does not live in the kernel on macOS or iOS.
- Bitcoin_McPonzi 9y agoI'm not sure either Y Combinator News nor the linked site are "major publications". It is news, because there's a _completely passive_ way to crash a device, and crashes nearly always will allow for unauthorized code execution, given enough resources to work on the problem. You could launch a DOS attack on phones this way, and we all know that Cell Phones are how we're warned about emergencies, etc. For what it's worth, Microsoft Edge, my default browser, had no problems with this page.
- danso 9y agoThe BBC is the largest broadcaster in the world.
- zackify 9y agoMy iPhone X wont even open imessages after trying to delete two texts with this message, i would say its a pretty big problem
- 9y ago
- rspeer 9y agoAnyone got any information on how the text rendering bug actually works (not just hand-waving it away as "oh it's UTF-8")? I can see that the file alternates between segments of: - Repetitions of the glyph "t̴́̍̒", which is a lowercase t with a combining tilde overlay, an acute accent, a vertical line above, and a turned comma above - Random-looking ASCII characters with lots of apostrophes (spelled as ' in the HTML) - Short sequences of spaces, non-breaking spaces, and zero-width joiners - Occasional emoji The "t̴́̍̒"s manage to slow down my terminal and glitch its rendering a bit. Is it that they're unexpectedly tall? But we've had zalgo-text for a while and it hasn't actually crashed devices.
- korzun 9y agoI believe it might have something to do with sizing down/padding of the parent elements that attempt to contain the out of spec characters.
- boombip 9y agoI find it unexpectedly hilarious that we now have issues that cannot be fully described without running the risk of crashing our machines. Its as if there are certain unholy words that could cause us to faint if we were to utter them.
- Infernal 9y agoUnicode basilisks?
- B1FF_PSUVM 9y agohttps://en.wikipedia.org/wiki/BLIT_(short_story) https://en.wikipedia.org/wiki/BLIT_(short_story) (Langford's story and followup in the links)
- yesenadam 9y agoSounds right out of Gödel, Escher, Bach : Achilles: I see the dilemma now. If any record player—say Record Player X—is sufficiently high-fidelity, then when it attempts to play the song "I Cannot Be Played on Record Player X", it will create just those vibrations which cause it to break...So it fails to be Perfect. And yet, the only way to get around that trickery, namely for Record Player X to be of lower fidelity, even more directly ensures that it is not Perfect. It seems that every record player is vulnerable to one or the other of those frailties, and hence all record players are defective. (p77)
- matt-attack 9y agoI've noticed that iOS will only perform requests to links in iMessage if and only if the sender is in your contacts. If an unknown sender iMessages you a URL, iOS will not perform a request.
- w0rd-driven 9y agoThis again? It's eerily similar to https://m.huffpost.com/us/entry/7452324 https://m.huffpost.com/us/entry/7452324 (sorry for the mobile link). Only one other comment mentions the bug from 2015 that surprise, crashes the phone in the same way. It looks like this person just worked around the patch to cause it again.
- sigjuice 9y agoWhere is my textbombattack.com website and cute logo?
- omarforgotpwd 9y agoNot making any sort of comment on this issue or Apple, but I’m sure glad every bug I write isn’t covered in the news.
- LocalH 9y agoConsidering that this text causes issues on other platforms than just Apple (with differing levels of severity), I would posit that it's unfair to characterize this as an "Apple bug".