3 ms·
> allow an attacker to remotely compromise a phone at the baseband level Aren't modern phones supposedly securely separate the baseband from the OS (Android)?
by pflanze 4y ago
> allow an attacker to remotely compromise a phone at the baseband level
Aren't modern phones supposedly securely separate the baseband from the OS (Android)? Does this mean that voice and data can be intercepted, but at least other data might be safe?
- parker_mountain 4y agoAndroid pretty effectively enforces TLS as well. Also, aside from the surface level issues of a vuln like this, an attacker now has a serious foothold on the device, which is still very bad.
- brookst 4y agoPure speculation, but I would guess that the interfaces to baseband are not particularly hardened, so an attack on the phone from the baseband might be trivial. Or worse, the baseband might have a trusted channel to launch arbitrary code.
- pdoege 4y agoNo. The baseband can DMA what it wants, when it wants. The baseband PMIC can power what it wants when wants. The AP is the junior partner.
- flangola7 4y agoIOUMMU prevents this
- userbinator 4y agoNot on MTK chipsets, or at least the older ones I'm familiar with: https://github.com/varunchitre15/MT6589_kernel_source/blob/master/mediatek/platform/mt6589/kernel/drivers/dual_ccci/src/ccci_platform.c https://github.com/varunchitre15/MT6589_kernel_source/blob/m... Look at the enable_mem_access_protection function.
- notactuallyben 4y agoThis is not true on pretty much any phone post 2014ish. Pretty much all platforms have IOMMU's or similar separation mechanisms. source: did baseband vr commercially
- Analemma_ 4y agoBasebands have not had DMA for a long time. There can still be vulnerabilities, which it sounds like is what happened here, but there’s no DMA anymore on new phones.
- p_l 4y agoThat was (possibly still is) the case on Qualcomm integrated Application and Baseband SoCs, not on Exynos where baseband is the junior partner.