7 ms·
It's not exactly specific to the image preview code, but rather the code that handles the notification when receiving an iMessage. The attack mentioned in the
by t0ps0il 5y ago
It's not exactly specific to the image preview code, but rather the code that handles the notification when receiving an iMessage.
The attack mentioned in the Wired article[1] relies on iMessage asking the sandboxless Springboard[2][3] to deserialize a maliciously crafted field, included in the incoming iMessage, to escape the sandbox. This specific vulnerability doesn't appear to apply to other apps.
[1] https://googleprojectzero.blogspot.com/2019/08/the-fully-remote-attack-surface-of.html https://googleprojectzero.blogspot.com/2019/08/the-fully-rem...
[2] https://en.wikipedia.org/wiki/SpringBoard https://en.wikipedia.org/wiki/SpringBoard
[3] https://iphonedev.wiki/index.php/SpringBoard https://iphonedev.wiki/index.php/SpringBoard