4 ms·
I would be interested to know what the impact on Secure Enclave will be from this exploit. From quick googling it sounds like bootrom isn’t involved in booting
by NightMKoder 7y ago
I would be interested to know what the impact on Secure Enclave will be from this exploit. From quick googling it sounds like bootrom isn’t involved in booting SEP. One large change from the exploit though is unlocking isn’t required to jailbreak.
Aside from that though - are there any extra abilities gained that weren’t already accessible as root (i.e. jailbreak) in iOS?
- monocasa 7y agoReplacing the kernel is the big one. On current hardware, once the kernel is loaded, the DRAM controller has its own memory protection unit seperate from the CPUs' MMUs that's set once and then can't be modified until the next reboot. This is used to enforce that the code segment of the kernel can't be written to even if you have access to physical memory or the page tables. It might make the secure enclave easier to hack, just by having a nicer, democratized access to application kernel space. But AFAIK none of this directly affects the secure enclave as it has its own bootrom that's way smaller and mainly just cryptographically verfies and executes a blob loaded by the main kernel.