Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...
NSO group iPhone zero-click, zero-day exploit captured in the wild
161–170 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#162Earlier quoted context omitted.
You appear to be the one confused. I'm not confusing anything. The entire point of the exploits in question are to BREAK the privacy provided by messenger. Google doesn't provide any in the first place, and actively mines your data. Who needs an exploit when it's never encrypted in the first place? To further this: you realize NSO isn't selling these exploits to Russian kiddies to steal your bank info, right? These e…
It not being e2e-enxrypted doesn't mean that the Mexican army can read my messages.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#163Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.
>no wonder China is banning government officials from using their devices. Do you actually think security is the reason they are being banned? I think the reasons are far more political than technical.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#164Earlier quoted context omitted.
This is the frustrating part: that is cool from a technical perspective but terrifying when you think about this stuff being used to target journalists, activists, etc. Maybe not everyone gets the bone saw but some will - and from the sounds of it it’s people standing up to abusive people: > Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with interna…
What is frustrating is the NSO group continues to exist despite all the bad they do. How many people are they responsible for being on the receiving end of a bone saw?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#165> The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim. Man, iMessage is a security disaster for Apple. No matter how much work they do in other areas, it seems like they'll paying for a while for their decisions around the iMessage architecture.
iMessage is overall a lot more complicated and integrated than I like it to be. Want to switch accounts, you gotta log your entire user or device out of iCloud. Logging back in will often create issues. Using old Mac/iPhone OS versions creates issues. Messages and attachments are received separately by different devices, and weird things happen when one device is out of space. Deleting messages or blocking senders is…
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#166I’m, in no way, a security savvy but the above achievement must be a lot of work by the NSO group!
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#167My IphoneSE feels like the old Battlestar Galactica around these new phones
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#168Earlier quoted context omitted.
Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...
Apple isn’t going to have internal bounties that can compete with nation state budgets.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#169Earlier quoted context omitted.
I don't think the EU is that much concerned about E-waste. If they were, they would not waste their time with chargers and instead focus on appliances and cars.
It’s like different people can work on different legislations in parallel, you know?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#170Again a buffer overflow in image decoding, that sounds similar to the one from 2021 [1]. That one was wild, building a CPU out of primitives offered by an arcane image compression format embedded in pdf, to be able to do enough arithmetic to further escalate to arbitrary code execution! [1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Again buffer overflow in image decoding. Would think apple might just #threatmodel and #fuzz that to death... but you would be wrong. 2.7T market cap company can't do this...