iPhone Bug Allowed for Complete Device Takeover Over the Air
#1
Information 
Quote:Details tied to a stunning iPhone vulnerability were disclosed by noted Google Project Zero researcher Ian Beer. Apple patched the vulnerability earlier this year. But few details, until now, were known about the bug that could have allowed a threat actor to completely take over any iPhone within a nearby vicinity. The hack could of been preformed over the air without even interacting with the victim’s device.
 
Beer said he spent six months figuring out the “wormable radio-proximity exploit” during a time when quarantines due to the COVID-19 virus were in effect and he was “locked down in the corner” of his bedroom. On Tuesday he published a blog post detailing his discovery and the hack.
 
Specifically, he was able to remotely trigger an unauthenticated kernel memory corruption vulnerability that causes all iOS devices in radio-proximity to reboot, with no user interaction.

The issue existed because of a protocol in contemporary iPhone, iPad, Macs and Apple Watches called Apple Wireless Direct Link (AWDL), Beer explained in his post. This protocol creates mesh networks for features such as AirDrop and Sidecar so these devices can connect and serve their appointed function–such as beam photos and files to other iOS devices, in the case of AirDrop.

“Chances are that if you own an Apple device you’re creating or connecting to these transient mesh networks multiple times a day without even realizing it,” Beer noted in his post.

Read more: https://threatpost.com/iphone-bug-takeov...ir/161748/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
iPhone Bug Allowed for Complete Device Takeover Over the Air - by silversurfer - 03 December 20, 15:24

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Random YouTube Vidoes
Kool — 11:25
Google Chrome 147.0.7727.116/117
Google Chrome 147....harlan4096 — 11:00
Brave 1.89.143 (Chromium 147.0.7727.117)
Release v1.89.143 ...harlan4096 — 10:59
Ubuntu 26.04 LTS Resolute Raccoon is Her...
Canonical today an...harlan4096 — 10:58
Vivaldi 7.9 Build 3970.59
Vivaldi 7.9 Build ...harlan4096 — 10:56

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>