A deep dive into iOS Exploit chains found in the wild
googleprojectzero.blogspot.com
A deep dive into iOS Exploit chains found in the wild
1–10 of 202 posts
Re: A deep dive into iOS Exploit chains found in the wild
#2Re: A deep dive into iOS Exploit chains found in the wild
#3Re: A deep dive into iOS Exploit chains found in the wild
#4Re: A deep dive into iOS Exploit chains found in the wild
#5This is terrifying... most people do not hard reset their phones ever (even when upgrading). What are the odds that these payloads are floating around despite the exploits being patched?
"The implant binary does not persist on the device; if the phone is rebooted then the implant will not run until the device is re-exploited when the user visits a compromised site again. "
Re: A deep dive into iOS Exploit chains found in the wild
#6Outside of the great tech writeup, what is particularly interesting about this, to me, from a geopolitical perspective is the level of restraint.
The malicious actors in this case leveraged zero-days for iOS for years and yet do not seem to have overextended themselves or risk exposure by overly widening their intended targets. What I mean by this is: they clearly could have chosen to gain a massive infection rate by combining this with hacking a well-known popular site, or even pulling more visits from (say) social media, but instead the malicious actor chose to limit their intended recipients to run the exploits for a smaller set of targets for much longer while remaining undetected.
This, to me, hints at a state-actor with specific intent.
Re: A deep dive into iOS Exploit chains found in the wild
#7Re: A deep dive into iOS Exploit chains found in the wild
#8Re: A deep dive into iOS Exploit chains found in the wild
#9These are fascinating. It would be very interesting to know what the character and subject matter of the infecting sites were. Outside of the great tech writeup, what is particularly interesting about this, to me, from a geopolitical perspective is the level of restraint. The malicious actors in this case leveraged zero-days for iOS for years and yet do not seem to have overextended themselves or risk exposure by ove…
Re: A deep dive into iOS Exploit chains found in the wild
#10It's staggering how systematically broken IOKit remains.