3 ms·
They state that they were unable to capture the follow-on stages of the Android chain, they only got the initial execution component. Which means there’s missi
by fullspectrumdev 3y ago
They state that they were unable to capture the follow-on stages of the Android chain, they only got the initial execution component.
Which means there’s missing a sandbox escape and privilege elevation bug.
Also yes while delivery here was apparently ISP level MiTM using lawful intercept capabilities, there’s no reason the exploit couldn’t be delivered as a 1click via a phishing link.