Unpatched iPhone Bug Allows Remote Device Takeover
#1
Information 
Quote:A vulnerability in Apple iOS opens the door to remote code execution (RCE), researchers found. The assessment is a revision from a previous understanding of the flaw that viewed it as a low-risk (and somewhat wacky) denial-of-service (DoS) problem affecting iPhone’s Wi-Fi feature.
 
Apple fixed the original DoS issue with iOS 14.6, without issuing a CVE. But when ZecOps analyzed the bug, researchers found that it could be used for RCE without little interaction with the victim – and that the attack worked on fully patched iPhones.
 
A successful exploit of the bug, which ZecOps dubbed “WiFiDemon,” would allow an attacker to take over the phone, install malware and steal data. It’s expected to be patched in the next week or so, according to some sources. 

The original DoS issue is a string-format bug discovered by researcher Carl Schou, who found that connecting to an access point with the SSID “%p%s%s%s%s%n” would disable a device’s Wi-Fi.

String-format problems occur when operating systems mistakenly read certain characters as commands: In this case, the “%” combined with various letters.
“My iPhone permanently disabled it’s [sic] Wi-Fi functionality,” Schou wrote in his writeup, in June. “Neither rebooting nor changing SSID fixes it :~)”
 
It can, however, be fixed by resetting the Wi-Fi feature in settings – something that wipes out all saved passwords, but which will restore Wi-Fi connections.
 
ZecOps said that a user would need to connect to a malicious access point for the bug to be exploited. But for earlier iPhone releases, there’s no need to lure a victim in: The Auto Join feature is turned on by default on iPhones, allowing them to automatically connect to available Wi-Fi networks in the background. Thus, an attacker would only need to set up an open, non-password-required malicious SSID within range of the target, and then sit back and wait.
 
An anonymous researcher was credited with finding the zero-click aspect of the bug, a fix for which occurred in iOS 14.4.

Read more: Unpatched iPhone Bug Allows Code Execution | Threatpost
[-] The following 2 users say Thank You to silversurfer for this post:
  • dinosaur07, harlan4096
Reply


Messages In This Thread
Unpatched iPhone Bug Allows Remote Device Takeover - by silversurfer - 20 July 21, 12:22

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
ESET 19.1.12.0
Changes in 19.1.12...harlan4096 — 14:49
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Google Chrome 146.0.7680.177/178
Google Chrome 146....harlan4096 — 07:22

[-]
Birthdays
Today's Birthdays
avatar (44)lamSouse
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (41)alapesihy
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>