Live data from Hacker News

A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

googleprojectzero.blogspot.com

1–10 of 360 posts

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#3
This is mind boggling. NSO used a compression format's instructions to create logic gates and then from there "a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations", all within a single pass of decompression. Combine this with a buffer overflow and you've got your sploit.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#7
post #4
post #2

Ok, they apparently made a VM using just the JBIG2 logical operators, that’s both hilarious and amazing. Still hate NSO though.

Not just a VM - effectively a computer. Holy crap that's amazing (ly evil).

Right? I was using VM as a short hand - it is after all a virtual just more virtual than usual :)

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#8

Am I reading this right? Google engineers are fixing apple software?

Project Zero is a team of security analysts employed by Google tasked with finding zero-day vulnerabilities.

https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1

Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really high quality.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#9

Am I reading this right? Google engineers are fixing apple software?

yes, you are, and this isnt abnormal or require some form of temporary altruism.

google is incentivized by ad space, not hardware sales. a large portion of the users of google apps and search engine are using apple hardware.

Re: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

#10

Am I reading this right? Google engineers are fixing apple software?

Project Zero is a team of security analysts employed by Google tasked with finding zero-day vulnerabilities. https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1 Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really hig…

how does Google benefit from this?
Post reply on HN