Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

121–130 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#122
post #109

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…

What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#123
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#124
post #38
post #23

Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.

Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

>Please... Androids no better.

The Pixel is.

>At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.

And the Pixel would have the patch released quicker.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#125
post #17

Earlier quoted context omitted.

It does. The page even recommends lockdown mode as a mitigation for affected parties (people who aren't updated)

I think that is a general recommendation in the linked post, not specifically for this issue.

There is an update just issued that is at the bottom of the page. It confirms that lockdown prevents this specific attack.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#126
I appreciate that a solution is for people to update immediately. It really makes me wonder if my Android phones over the years have had 1-days exploited by the sheer incompetence of the ecosystem in updating phones.

Not much confidence when you get an update with security patches from 2-3 months ago.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#127
post #70

Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Which actually makes me more sympathetic to Chrome not (yet) adopting JPEG-XL.

Don't get me wrong, I think JPEG-XL is a great idea, but to everyone saying "how can supporting another image format possibly do any harm", this is the answer.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#128
post #4

Earlier quoted context omitted.

At least they’re trying? Meanwhile Google has spent 2 decades refusing to release a messenger that encrypts by default because they think they should be able to mine all your personal conversations. I take that back, they announced encrypted messaging, then never released it, then probably fired the engineer who said it’d be a feature in allo (or whatever their last attempt was).

No that's not true. Google just fails miserably at anything social, but almost every chat attempt from them eas encrypted, and now they are pushing RCS, which is also E2EE.

So YouTube isn't a social platform?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#129

Earlier quoted context omitted.

And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.

I would describe a one click rootkit as terrifying as opposed to wonderful.

It was a different time. There was nothing on my iPod touch that mattered enough.
Post reply on HN