4 ms·
The code signing system on iOS doesn't let you dynamically add code to your app. I am also very curious about what "it is a downloader" means - if the architect
by szc 7y ago
The code signing system on iOS doesn't let you dynamically add code to your app. I am also very curious about what "it is a downloader" means - if the architecture of WhatsApp means that it has a built in; externally accessible / triggerable, network capable scripting engine then that is really, really bad. I would be really worried about that app if it is true.
[added] The report writer may not have chosen the best way to phrase this. What it might mean is that the investigators believe that the "malicious" payload that compromises WhatsApp is in that part of the message, not in the video. As they weren't able to get that piece, they weren't able work out how the exploit worked.
- m0zg 7y agoIt probably isn't true though. The whole document is full of red flags to me from just purely a position of a computer literate person, and I'm not even an expert at this.
- szc 7y agoSorry, I added some additional text after you replied. I now think the report is just poorly phrased and it should have said "exploit" instead of "downloader". It is very likely the exploit, once run, did download more stuff.