3 ms·
According to the article the flood of exploits has more to do with iMessage and safari attack surface and not necessarily the OS.
by dev_dull 7y ago
According to the article the flood of exploits has more to do with iMessage and safari attack surface and not necessarily the OS.
- cjbprime 7y agoThat's what I was talking about too. The kernels of both have source available, Linux vs xnu. But the userland of Android is mostly memory-safe Java, and the userland of iOS (e.g. iMessage) is mostly memory-unsafe ObjC. The kind of marshalling and memory management exploits described in the p0 posts are very unlikely to happen on the Android side.
- 0x0 7y agoLots of android system/userland libraries are written in C or C++. Stagefright is but one example of a high impact vulnerability reachable from SMS/MMS on Android.