5 ms·
No, most are zero-click silent exploits. They own your phone persistently then delete the incoming message that pwned you.
by zionic 5y ago
No, most are zero-click silent exploits. They own your phone persistently then delete the incoming message that pwned you.
- fshbbdssbbgdd 5y agoAre other messaging apps on iOS ever getting RCE exploits like this? Can’t they sandbox iMessage so this isn’t possible no matter how many bugs the app has?
- can16358p 5y agoThey actually did it with iOS 14 (named Blastdoor) but apparently it's not helping much. Considering how tightly integrated iMessage is with iOS, it doesn't seem likely that it will really be fixed in an easy manner.
- judge2020 5y agoIronic that Apple limiting their apps in the same way they limit 3p apps would've likely solved this vulnerability, unless the attack was only "0-click access to full chat.db"
- Godel_unicode 5y agoExcept there are tons of examples of iOS sandbox escapes over the last few years. I definitely don't consider iOS sandboxing a security control at this point.
- marcan_42 5y agoThey do limit their own apps (they even specifically sandboxed part of the iMessage handling, more than a standard app). The exploit chains that NSO uses include sandbox escapes.
- Drew_ 5y agoWhatsApp also had one: https://www.facebook.com/security/advisories/cve-2019-3568 https://www.facebook.com/security/advisories/cve-2019-3568
- dagmx 5y agoIt's possible other apps are getting exploits, but those are less valuable since they're not installed by default. As it stands, the most recently published information about the exploits were in the image parsers. So any app that used the default image parsers may have been affected, but might not have the same ability to escalate the exploit via other exploits. Plus you get back to the lack of ubiquity of the app, and the difficulty in targeting.
- BelenusMordred 5y ago> zero-click Literally worth millions of dollars on the wholesome greymarkets these days, possibly the most prized, just in case anyone was wondering.
- spicybright 5y agoHow so?
- pewpew_ 5y agoYou don’t need any input from the user/target. Once the malicious code reaches the device the exploit works its magic.
- BelenusMordred 5y agoAn open source cellular modem firmware is long overdue, but there's no government on Earth that would be keen on allowing it to happen, the best we have is 2G/3G stuff that has been illegally leaked and reverse engineered. A lot of dragons lurking in the dark there.
- mschuster91 5y agoThe network side is already covered by OpenBTS and srsRAN - I believe the latter is already including 5G. Wonder what's blocking the client side. Power efficiency? No target market since cheap LTE sticks can be had for under 20€ apiece?
- ufmace 5y agoThe modem firmwares might be old and hairy, but is there any evidence that they have been used to actually compromise phones? All of the investigations that I can recall reading have been exploits in the phone OS application code.
- fsflover 5y agohttps://linuxsmartphones.com/hackers-develop-open-source-firmware-for-the-pinephone-modem-use-it-to-make-phone-calls/ https://linuxsmartphones.com/hackers-develop-open-source-fir...
- marcan_42 5y agoIt's actually not persistent; AIUI Pegasus these days is designed to be ephemeral to avoid forensic analysis. If you reboot your phone it's gone (but they can just own you again with another message). Of course, most people don't reboot their phones very often.