5 ms·
> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence,
by toasterblender 3y ago
> What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability.
This is such a crucial point. Forced to read between the lines of the blog post (because the above information is missing), it sounds like there are currently unpatched issues in Android revolving around this?
- fullspectrumdev 3y agoLikely yes, they were unable to capture the following stages so they don’t know what was exploited after gaining initial execution within the chrome sandbox. Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”.
- vdfs 3y ago> Likely there’s a chrome sandbox escape and a kernel exploit remaining “unknown and unpatched”. There is certainly many of those that we don't know about, if this was done in Egypt, imagine what a 3 letters agency have
- staplers 3y agoWouldn't be a stretch to assume this is forced by 3 letter agencies and it's details leaked for sale on an exclusive dark web. Think of all the insidious corruption we find out about via declassification 50 years later. It's not like human nature has changed.
- conradev 3y agoEvery government with money has exploits for every device imaginable. The going price was $1m for a full exploit chain on iPhone a while ago, and I’m sure it’s gone up, but I’m also sure it is minuscule compared to the amount of money governments have. Everyone should assume this is fact, and not imagine some secret spy world. If you ever become interesting enough to hack, you will be, and there is little recourse (currently)
- CobrastanJorji 3y agoKinda surprising that Apple wouldn't be the highest bidder for a full exploit chain. They've been known to give out $100,000 bug bounties, but you'd think one million would be a pretty good deal for closing a vulnerability vs having it sold to companies that professionally surveil people.
- apienx 3y agoOne million dollars is what some states pay _per target_. Every major black hat group operates with the blessing of some state. It’s about more than just money. Actual exploits are probably traded for “favours” (e.g. votes in international bodies, collaboration on thorny dossiers, extraditions, etc.). The infiltration of electronic communication is a major aspect in determining a state’s level of “soft power” and - in a software-run world - its weight only increases.
- taway1237 3y ago>Every major black hat group operates with the blessing of some state. Citation needed. As far as I know that's true. Yes, some groups cooperate with the state (true in Russia after the escalation of the war in Ukraine, for example). But that's certainly not true for everyone - not every group has uses as an APT unit, most are just common criminals.
- bboygravity 3y agoI'd go a step further and state: everybody is interesting enough to fully automatically hack. I have 0 doubt that literally everybody is being scraped by 1 or more governments and/or companies. Because if they can, why not?
- computerfriend 3y agoBecause every time you do it, you run the risk of discovery. This can be expensive (you burn your exploit) and politically embarrassing.
- 3y ago
- wyldfire 3y agoIs it possible that it was detected but without a sandbox escape? would it still be described as "an exploit" if so?
- saagarjha 3y agoYes.
- fredgrott 3y agoRead it again, no sandbox attack on Android MITM and one time link attack only .
- saagarjha 3y agoThat’s all they were able to gather.
- throwawaaarrgh 3y agoI mean there are always unpatched issues in everything... There's nothing you can do, whether you know about it or not. You have to just assume you're always actively being exploited at some level
- vardump 3y agoCan be multiple vendor specific exploits.