Live data from Hacker News

Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

macrumors.com

1–10 of 182 posts

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#2
>A third security researcher, Stefan Esser said that people should be careful what apps they download from the App Store right now. "Any such app could have a copy of the jailbreak in it," he wrote on Twitter.

Seems a bit overblown when there's a review process in place. I'm sure it's not infallible, but still..

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#3
post #2

>A third security researcher, Stefan Esser said that people should be careful what apps they download from the App Store right now. "Any such app could have a copy of the jailbreak in it," he wrote on Twitter. Seems a bit overblown when there's a review process in place. I'm sure it's not infallible, but still..

It's happened before, and it's probably not super easy for Apple to do static binary analysis to determine if an app is going to make exactly the bad syscalls necessary for the jailbreak gated behind an undisclosed trigger functionality.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#4
post #2

>A third security researcher, Stefan Esser said that people should be careful what apps they download from the App Store right now. "Any such app could have a copy of the jailbreak in it," he wrote on Twitter. Seems a bit overblown when there's a review process in place. I'm sure it's not infallible, but still..

Can a review really check for this? Aren't there obfuscation methods and ways to delay the trigger of the exploit? It could wait for a special network package to start the exploit.

For iOS 9.3.3 there even was an app in the App Store, that could jailbreak your phone. (PG Client)

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#5
post #2

>A third security researcher, Stefan Esser said that people should be careful what apps they download from the App Store right now. "Any such app could have a copy of the jailbreak in it," he wrote on Twitter. Seems a bit overblown when there's a review process in place. I'm sure it's not infallible, but still..

[deleted]

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#6
It's unfortunate how Apple and Google approach device ownership, and their attitude towards the concept of general computing is concerning.

We do not control our own devices, we cannot stop certain processes on them, and we do not know where our personal data is sent.

We either have to flash ROMs from questionable sources and apply temporary exploits to get some kind of resemblance of control of our own devices, or we have to spend years to learn the skills to unlock these systems ourselves.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#8
post #2

>A third security researcher, Stefan Esser said that people should be careful what apps they download from the App Store right now. "Any such app could have a copy of the jailbreak in it," he wrote on Twitter. Seems a bit overblown when there's a review process in place. I'm sure it's not infallible, but still..

Yes, to some extent people should be worried about apps potentially containing exploits, but then again they should be more worried about 0-days than a known vulnerability.

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#9
I got a lot of flak here recently for suggesting that maybe security researchers shouldn't be publishing PoCs or deep vulnerability details literally 1 week after the vendor issues a patch.

Here's to hoping that, now that this happened, someone will give this idea another consideration...

(P.S. for those wondering: apparently this is CVE-2019-8605: https://bugs.chromium.org/p/project-zero/issues/detail?id=18...)

Re: Apple Accidentally Unpatches Vulnerability, Leading to New iOS 12.4 Jailbreak

#10
post #9

I got a lot of flak here recently for suggesting that maybe security researchers shouldn't be publishing PoCs or deep vulnerability details literally 1 week after the vendor issues a patch. Here's to hoping that, now that this happened, someone will give this idea another consideration... (P.S. for those wondering: apparently this is CVE-2019-8605: https://bugs.chromium.org/p/project-zero/issues/detail?id=18... )

But it's been 3 months since the vendor first issued a patch!
Post reply on HN