Kernel RCE in iOS/macOS with ICMP
1–10 of 68 posts
Re: Kernel RCE in iOS/macOS with ICMP
#2Edit: An indirect archive, because apparently archive.is does not allow localStorage access either. http://archive.is/yuIV5
Re: Kernel RCE in iOS/macOS with ICMP
#3As an aside:
> Even on a Mac, XNU is highly non-trivial to build.
I find it to be an extremely sad state of affairs when it requires scouring the internet for a blog post from a Darwin engineer to build an outdated XNU :(
Re: Kernel RCE in iOS/macOS with ICMP
#4Re: Kernel RCE in iOS/macOS with ICMP
#5Ok, yeah, not exactly the same, but humor me. It's a Halloween undead miracle!
Re: Kernel RCE in iOS/macOS with ICMP
#6TL;DR: Heap buffer overflow in the network stack allowed for sending ICMP packets that would crash devices. Bug was marked as "RCE" because it's possible that it could be used for code execution, though the current PoC only causes a crash. Bug has been reported to Apple and fixed in iOS 12 and macOS Mojave 10.14. There's an excellent drawing by the author at the end of the author summarizing the exploit ;) As an asid…
Re: Kernel RCE in iOS/macOS with ICMP
#7TL;DR: Heap buffer overflow in the network stack allowed for sending ICMP packets that would crash devices. Bug was marked as "RCE" because it's possible that it could be used for code execution, though the current PoC only causes a crash. Bug has been reported to Apple and fixed in iOS 12 and macOS Mojave 10.14. There's an excellent drawing by the author at the end of the author summarizing the exploit ;) As an asid…
Re: Kernel RCE in iOS/macOS with ICMP
#8TL;DR: Heap buffer overflow in the network stack allowed for sending ICMP packets that would crash devices. Bug was marked as "RCE" because it's possible that it could be used for code execution, though the current PoC only causes a crash. Bug has been reported to Apple and fixed in iOS 12 and macOS Mojave 10.14. There's an excellent drawing by the author at the end of the author summarizing the exploit ;) As an asid…
Apparently it was actually already fixed in ios 12.0 and macOS 10.14.0 but retroactively added to the security notes for those releases only just now.
Re: Kernel RCE in iOS/macOS with ICMP
#9TL;DR: Heap buffer overflow in the network stack allowed for sending ICMP packets that would crash devices. Bug was marked as "RCE" because it's possible that it could be used for code execution, though the current PoC only causes a crash. Bug has been reported to Apple and fixed in iOS 12 and macOS Mojave 10.14. There's an excellent drawing by the author at the end of the author summarizing the exploit ;) As an asid…
and yet I always hear the argument, "but it's open source, just like Linux".
Re: Kernel RCE in iOS/macOS with ICMP
#10TL;DR: Heap buffer overflow in the network stack allowed for sending ICMP packets that would crash devices. Bug was marked as "RCE" because it's possible that it could be used for code execution, though the current PoC only causes a crash. Bug has been reported to Apple and fixed in iOS 12 and macOS Mojave 10.14. There's an excellent drawing by the author at the end of the author summarizing the exploit ;) As an asid…