4 ms·
Like an exploit where all you need to do is enter the target's phone number to compromise their phone?
by mont 8y ago
Like an exploit where all you need to do is enter the target's phone number to compromise their phone?
- zaroth 8y agoTFA says they need to send the target a text message. The exploit must be something like a buffer overflow in iMessage. Which we know bugs like this have been fixed. Remember the text of death which could crash any iPhone from a couple years ago?
- tapland 8y agoWasn't that in may? Time flies.
- brobinson 8y agoAre you thinking of the "Stagefright" bug that did RCE via SMS on Android devices? Or maybe the Chinese censorship code that crashed iOS when people sent the Taiwanese flag emoji? 🇹🇼
- jeroenhd 8y agoDon't forget the Stagefright-like bug in iOS where a malformed TIFF file could lead to remote code execution!
- AnimalMuppet 8y ago"Bugs like this have been fixed" != "all bugs like this have been fixed". That is, some similar bugs having been fixed does not make such an exploit impossible.
- neom 8y agoI think more that they manage to find these exploits and rapidly build infrastructure around it to make it useful.
- ttsda 8y agoThey don't need to be very fast... the NSA is known to sit on vulnerabilities for years.