NSO group iPhone zero-click, zero-day exploit captured in the wild
1–10 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#2Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#3Man, iMessage is a security disaster for Apple. No matter how much work they do in other areas, it seems like they'll paying for a while for their decisions around the iMessage architecture.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#4> The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim. Man, iMessage is a security disaster for Apple. No matter how much work they do in other areas, it seems like they'll paying for a while for their decisions around the iMessage architecture.
I take that back, they announced encrypted messaging, then never released it, then probably fired the engineer who said it’d be a feature in allo (or whatever their last attempt was).
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#5Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#6Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#7Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#8> The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim. Man, iMessage is a security disaster for Apple. No matter how much work they do in other areas, it seems like they'll paying for a while for their decisions around the iMessage architecture.
At least they’re trying? Meanwhile Google has spent 2 decades refusing to release a messenger that encrypts by default because they think they should be able to mine all your personal conversations. I take that back, they announced encrypted messaging, then never released it, then probably fired the engineer who said it’d be a feature in allo (or whatever their last attempt was).
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#9These fixes came out today, apparently timed with the announcement, make sure updates are applied for you and yours. https://support.apple.com/en-us/HT201222
As far as I know, any parsing code for iMessages should run within the BlastDoor sandbox – is there another vulnerability in the chain that is not reported here?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#10Earlier quoted context omitted.
At least they’re trying? Meanwhile Google has spent 2 decades refusing to release a messenger that encrypts by default because they think they should be able to mine all your personal conversations. I take that back, they announced encrypted messaging, then never released it, then probably fired the engineer who said it’d be a feature in allo (or whatever their last attempt was).
Isn't Messages E2E by default?