iOS 18.6.1 0-click RCE POC
github.com
iOS 18.6.1 0-click RCE POC
1–10 of 61 posts
Re: iOS 18.6.1 0-click RCE POC
#2Re: iOS 18.6.1 0-click RCE POC
#3Re: iOS 18.6.1 0-click RCE POC
#4Re: iOS 18.6.1 0-click RCE POC
#5Re: iOS 18.6.1 0-click RCE POC
#6Re: iOS 18.6.1 0-click RCE POC
#7I'm actually really curious about how the ITW exploit for this CVE worked; the OOB write is quite obvious in hindsight but going from OOB write to execution on iOS is very much not easy these days, and going from OOB write to sandbox escape should be extremely hard, especially since I thought (?) all image previews in iMessage should be behind BlastDoor. There's a lot of interesting stuff that's still missing here.
Re: iOS 18.6.1 0-click RCE POC
#8I wonder how much this would be worth for Zerodium
Re: iOS 18.6.1 0-click RCE POC
#9Where's the 0-click or the RCE here? I'm actually really curious about how the ITW exploit for this CVE worked; the OOB write is quite obvious in hindsight but going from OOB write to execution on iOS is very much not easy these days, and going from OOB write to sandbox escape should be extremely hard, especially since I thought (?) all image previews in iMessage should be behind BlastDoor. There's a lot of interesti…
See my other comment. There's an exploit in the wild that uses this bug to get RCE, but this specific example just causes a crash.