3 ms·
If you successfully exploit a kernel vulnerability, you don't need an iMessage bug.... you can pretty much access whatever you want.
by CyberRage 5y ago
If you successfully exploit a kernel vulnerability, you don't need an iMessage bug....
you can pretty much access whatever you want.
- saagarjha 5y agoMy point is that the thing you would often do after that is go after people's iMessages anyways.
- CyberRage 5y agoI think you misunderstand how things work on modern mobile OS. You don't need to access the messages app in order to get access to the messages. it's the opposite actually, the messaging app needs permissions for the system level messaging component.
- saagarjha 5y agoI assure you that I know enough to at least hold an intelligent conversation on mobile security. On iOS there is no "system level messaging component". (i)Messages are stored in a SQLite database that is protected via entitlements and sandboxing; the Messages app is given the ability to access it legitimately. Attackers can either exploit the Messages itself and (via code execution in that process) grab a user's messages, or they can exploit something else (such as the web content process) and then escalate privileges from there to bypass the sandbox.
- CyberRage 5y agoAgain, if you get a kernel exploit, you don't need access to the messaging app or to escalate privileges. you're already root. you can access any component without much restriction. How the data is stored has nothing to do with this
- saagarjha 5y agoThis is correct. My point is that you would want to access messages data after doing that.
- CyberRage 5y agoSo let's circle back to the original question. Pwning the app will only provide access to whatever permission it has and we are still sandboxed. Pwning a kernel module\driver will provide access to everything whether its messaging, call logs, pictures etc. we are not sandboxed, we don't need an LPE exploit. I think the priority is clear.
- saagarjha 5y agoExploiting the kernel is obviously always desirable, but it's not always possible.