Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

Google engineer demonstrate how he could get full control and copy all data from 25 iPhones without touching them

iPhone security? Hmmm... In this demo I remotely trigger an unauthenticated kernel memory corruption vulnerability which causes all iOS devices in radio-proximity to reboot, with no user interaction. Over the next 30'000 words I'll cover the entire process to go from this basic demo to successfully exploiting this vulnerability in order to run arbitrary code on any nearby iOS device and steal all the user data

One of the geniuses working for Google on Project Zero wrote on his blogpost and on his YouTube videos:

Introduction
Quoting @halvarflake's Offensivecon keynote from February 2020:

"Exploits are the closest thing to "magic spells" we experience in the real world: Construct the right incantation, gain remote control over device."

For 6 months of 2020, while locked down in the corner of my bedroom surrounded by my lovely, screaming children, I've been working on a magic spell of my own. No, sadly not an incantation to convince the kids to sleep in until 9am every morning, but instead a wormable radio-proximity exploit which allows me to gain complete control over any iPhone in my vicinity. View all the photos, read all the email, copy all the private messages and monitor everything which happens on there in real-time.

The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine.

Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with.

Imagine the sense of power an attacker with such a capability must feel. As we all pour more and more of our souls into these devices, an attacker can gain a treasure trove of information on an unsuspecting target.

What's more, with directional antennas, higher transmission powers and sensitive receivers the range of such attacks can be considerable.

I have no evidence that these issues were exploited in the wild; I found them myself through manual reverse engineering. But we do know that exploit vendors seemed to take notice of these fixes. For example, take this tweet from Mark Dowd, the co-founder of Azimuth Security, an Australian "market-leading information security business":

Watch the videos and read his full post here.

AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

UK and EU Reach Agreement on Gibraltar's Schengen Integration
0:00
0:00
Open
UK and EU Reach Agreement on Gibraltar's Schengen Integration
0:00
0:00
Close
UK and EU Reach Agreement on Gibraltar's Schengen Integration
Israeli Finance Minister Imposes Banking Penalties on Palestinians
U.S. Inflation Rises to 2.4% in May Amid Trade Tensions
Trump's Policies Prompt Decline in Chinese Student Enrollment in U.S.
Global Oceans Near Record Temperatures as CO₂ Levels Climb
Trump Announces U.S.-China Trade Deal Covering Rare Earths
Smuggled U.S. Fuel Funds Mexican Cartels Amid Crackdown
Austrian School Shooting Leaves Nine Dead in Graz
Bezos's Lavish Venice Wedding Sparks Local Protests
Europe Prepares for Historic Lunar Rover Landing
Italian Parents Seek Therapy Amid Lengthy School Holidays
British Fishing Vessel Seized by France Fined €30,000
Dutch Government Collapses Amid Migration Policy Dispute
UK Commits to 3.5% GDP Defence Spending Under NATO Pressure
Germany Moves to Expedite Migrant Deportations
US Urges UK to Raise Defence Spending to 5% of GDP
Israeli Forces Intercept Gaza-Bound Aid Vessel Carrying Greta Thunberg
IMF Warns of Severe Global Trade War Impacts on Emerging Markets
Low Turnout Jeopardizes Italy's Citizenship Reform Referendum
Transatlantic Interest Rate Divergence Widens as Trump Pressures Powell
EU Lawmaker Calls for Broader Exemptions in Supply Chain Legislation
France's Defense Spending Plans Threatened by High National Debt
European Small-Cap Stocks Outperform U.S. Rivals Amid Growth Revival
Switzerland Proposes $26 Billion Capital Increase for UBS
Germany's Merz Signals Continued U.S. Reliance After Meeting with Trump
Trump Administration Issues New Travel Ban Targeting 12 Countries
Man Group Mandates Full-Time Office Return for Quantitative Analysts
JPMorgan Warns Analysts Against Accepting Future-Dated Job Offers
Builder.ai Faces Legal Scrutiny Amid Financial Misreporting Allegations
Japan Grapples with Rice Shortage Amid Soaring Prices
Goldman Sachs Reduces Risk Exposure Amid Market Volatility
HSBC Chairman Mark Tucker to Return to AIA as Non-Executive Chair
Israel Confirms Arming Gaza Clan to Counter Hamas Influence
Judge Blocks Trump's Ban on International Students at Harvard
Trump Proposes Travel Ban on 'Uncontrolled' Countries
Global News Roundup: From Ukraine's strategic military strikes and Russia's demands and Tensions Escalate in Ukraine, to serious legal issues faced by Britons in Bali and Trump's media criticism, the latest developments highlight a turbulent landscape
Majority of French Voters View Macron's Presidency as a Failure
Hungary Partners with China to Boost Electric Vehicle Production
‘Vibe Coding’ Emerges as the New DIY Trend
AI Pioneer Yoshua Bengio Warns Models Can Deceive Users
Big Four Firms Rush to Create AI Auditing Systems
Musk’s xAI Pursues $113 Billion Valuation in New Share Sale
Walmart Increases Revenue Despite Shrinking Workforce
Hims & Hers Plans UK and EU Launch of Replica Obesity Drugs
Toyota to Acquire Supplier in $33 Billion Buyout
U.S. Reduces Military Presence in Syria
Trump Demands Iran End All Uranium Enrichment in Nuclear Talks
BlackRock-Backed Fintech Aims to Become Europe’s Charles Schwab
China Accuses US of Violating Trade Truce
Europe's Strategic Push to Challenge Dollar Dominance
×