3 ms·
> All they need to do is send you a message and you are compromised. How does that even work?
by coderedart 3y ago
> All they need to do is send you a message and you are compromised.
How does that even work?
- filleokus 3y agoFor example by finding an exploit in parsers of media "attachments": https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- Muromec 3y agoIt works the usual way -- you make a payload that, when processed by a buggy code, executes itself. If the buggy code happens to be SMS packet parser, image decoder, text rendering, blocklist check or another 2 millions of things that happen to show you incoming SMS (or even better, flash message, or something not visible to user), then you don't have to click on it. I mean if the bug in the browser, you have to visit the page to have the payload get to you, but it's a phone. A device for other people to contact you.
- nwsm 3y agoHere's an example of a real iOS SMS bug exploit delivered by SMS- https://www.forbes.com/sites/amitchowdhry/2015/05/29/apple-effective-power-bug/?sh=b86351c313ae https://www.forbes.com/sites/amitchowdhry/2015/05/29/apple-e...