3 ms·
JBIG2 is what the NSO group exploited as part of their zero-click iMessage exploit. Google zero has a good write up if anyone hasn’t heard about it yet—it’s sup
by OGWhales 3y ago
JBIG2 is what the NSO group exploited as part of their zero-click iMessage exploit. Google zero has a good write up if anyone hasn’t heard about it yet—it’s super cool:
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- nocoiner 3y agoThis is so very much worth a read. It is almost literally mind blowing once you realize how deep the exploit goes.
- Uptrenda 3y ago>Practical circuits >JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent. >The bootstrapping operations for the sandbox escape exploit are written to run on this logic circuit and the whole thing runs in this weird, emulated environment created out of a single decompression pass through a JBIG2 stream. It's pretty incredible, and at the same time, pretty terrifying. Wow... that's really out of the box. They built their own VM from a JBIG compression stream vuln and wrote an exploit to run on it... Not bad.