3 ms·
As explained in the introduction, this escape used only logic bugs. So rust would still be affected
by invokestatic 5y ago
As explained in the introduction, this escape used only logic bugs. So rust would still be affected
- ghayes 5y agoFrom the first paragraph: > By sending a .gif iMessage attachment (which was really a PDF) NSO were able to remotely trigger a heap buffer overflow in the ImageIO JBIG2 decoder.
- greiskul 5y agoYes, this attack had multiple stages. First stage is to get something running, and to do that they do use a memory bug that Rust would prevent. The second stage is the sandbox escape that the post describes which is done with only logic bugs, so that would still be vunerable if written in Rust. While rewritting the world is not possible, all these attacks show that definitely new systems should probably not be written in memory unsafe languages.
- O5vYtytb 5y agoThey're referring to a previously mentioned exploit: > Late last year we published a writeup of the initial remote code execution stage of FORCEDENTRY, the zero-click iMessage exploit attributed by Citizen Lab to NSO. The sandbox escape only uses logic bugs: > In this post we'll take a look at that sandbox escape. It's notable for using only logic bugs.