Earlier quoted context omitted.
They are.
They clearly are not, seeing what's happening.
NSO group iPhone zero-click, zero-day exploit captured in the wild
321–330 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#322These fixes came out today, apparently timed with the announcement, make sure updates are applied for you and yours. https://support.apple.com/en-us/HT201222
Interestingly, no kernel vulnerability or anything is mentioned. As far as I know, any parsing code for iMessages should run within the BlastDoor sandbox – is there another vulnerability in the chain that is not reported here?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#323Earlier quoted context omitted.
Software liability would effectively crush smaller companies, unable to keep up with the lawsuits, because they don't have billions in the bank.
Or you’d have separate rules, similar to how you can make kit cars or ultralight airplanes without being held to the same scrutiny as Boeing or GM.
The regulatory capture resulted in a pathological operating module that put over 346 in an early grave because they couldn't be arsed to not cut corners; then on top of ot all, there's no substantive finding of liability or wrongdoing.
Laws that are ultimately unenforced due to 2B2F might as well not exist at all.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#324Naive question, does apple have any way of detecting and informing users who are current victims of these types of exploits when security fixes are issued?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#325Here we go again... NSO Group has a long history of 0-click, 0-days against iMessage, and just a few months ago Kaspersky caught a different zero day iMessage exploit targeting their staff. If Apple repeatedly fails at securing their devices from an attack vector that has been demonstrated over, and over, and over... no wonder China is banning government officials from using their devices.
Please... Androids no better. At least Apple will have it patched within the year of discovery. Can't say the same for other Android vendors.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#326Earlier quoted context omitted.
And a much older bug with TIF rendering in iOS 4 used by jailbreakme.com back in the day. It was wonderful pressing a button in Safari and suddenly seeing my iPod touch reboot with Cydia installed.
Huh? I could've sworn the TIFF bug was during the iPhoneOS 1.x days. I recall jailbreakme's exploit using corrupted fonts in a PDF, not TIFF images. A quick Google search led me to this https://appleinsider.com/articles/10/08/03/browser_based_ios...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#327Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#328Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#329I find it interesting that most comments here are blaming the victim (Apple’s iMessage and by transitivity its users) rather than the aggressor (NSO and its users). How come NSO isn’t yet designated as a (cyber-)terrorist group worth hunting down and extinguishing?
If an air bag fails, you fault the manufacturer. They don’t escape responsibility by saying it’s the other drivers fault.
I’ll also add that Apple is not the victim here, the targeted end users are.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#330Earlier quoted context omitted.
They're slowly rewriting the whole thing in Swift which should eventually eliminate most of the non architectural attack vectors. Most of them were mitigated in iOS 14 where they did some rather large architectural changes. Edit: Further info: https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...
When I look at an initiative like BlastDoor, I'm struck by how unlikely it is that every other messaging app makes a similar investment on every platform. Does WhatsApp have a similar architecture? Has the Gmail app rewritten all its image parsers in a similar manner? Has Tinder? And sure, if you compromise WhatsApp you only get access to its internal memory and may not be able to escalate to other apps or OS storage…