Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New iPhone Exploit Uses Four Zero-Days
Schneier on Security ^

Posted on 01/15/2024 5:58:34 AM PST by FarCenter

Kaspersky researchers are detailing “an attack that over four years backdoored dozens if not thousands of iPhones, many of which belonged to employees of Moscow-based security firm Kaspersky.” It’s a zero-click exploit that makes use of four iPhone zero-days.

The most intriguing new detail is the targeting of the heretofore-unknown hardware feature, which proved to be pivotal to the Operation Triangulation campaign. A zero-day in the feature allowed the attackers to bypass advanced hardware-based memory protections designed to safeguard device system integrity even after an attacker gained the ability to tamper with memory of the underlying kernel. On most other platforms, once attackers successfully exploit a kernel vulnerability they have full control of the compromised system.

On Apple devices equipped with these protections, such attackers are still unable to perform key post-exploitation techniques such as injecting malicious code into other processes, or modifying kernel code or sensitive kernel data. This powerful protection was bypassed by exploiting a vulnerability in the secret function. The protection, which has rarely been defeated in exploits found to date, is also present in Apple’s M1 and M2 CPUs.

The details are staggering:

(Excerpt) Read more at schneier.com ...


TOPICS: News/Current Events
KEYWORDS:
Navigation: use the links below to view more comments.
first 1-2021-37 next last

1 posted on 01/15/2024 5:58:34 AM PST by FarCenter
[ Post Reply | Private Reply | View Replies]

To: FarCenter

The key takeaway here is “this is nation-state stuff” - cyber warfare, not some clever hackers in their bedrooms…


2 posted on 01/15/2024 7:14:37 AM PST by bigbob
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

Thanks for posting!

Once the javascript core library is modified to the attacker’s desire (this exploit was 11,000 minimized lines of code!) then game over. They could also see the entire user memory space (passwords in RAM, etc).

Used to read every one of these security updates back in the day - and the white papers. Now, it took me a year before I set up a voicemail message on my phone ;-)

Oh well, just upgraded to iOS 17.

These systems are too complex these days to be able to lockdown everything.


3 posted on 01/15/2024 7:16:20 AM PST by glorgau
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

I wonder if that is why my Apple iPhone 14 Pro is a piece of junk. Dropped calls, lagging dialing internet that freezes up.
Anybody else with a iPhone that is garbage?


4 posted on 01/15/2024 7:18:29 AM PST by ncfool (America has died we are living in the united socialist states of aMeriKa)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

If the FBI can penetrate your phone, other bad people can too.


5 posted on 01/15/2024 7:24:13 AM PST by Brian Griffin
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

A gigabyte of my 10GB monthly allocation was used up in the hour or so I’ve been online here.

I think it was for a Microsoft update.


6 posted on 01/15/2024 7:25:50 AM PST by Brian Griffin
[ Post Reply | Private Reply | To 1 | View Replies]

To: ncfool
Anybody else with a iPhone that is garbage?

Nope you're the only person on Earth to ever have an iPhone that had a problem...</kidding>

7 posted on 01/15/2024 7:28:12 AM PST by null and void (I identify as a conspiracy theorist. My personal pronouns are told/you/so.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ncfool

iPhone 12 here with T-Mobile. I suffer the same problems — calls that suddenly drop, calls that won’t connect, and periodic crappy voice quality. We cut our mobile bill in half by switching from Verizon to T-Mobile and that is exactly when the problems started.

I got my new iPhone a couple years ago and switched to T-Mobile at the same time. I drove my wife to the airport, and, on the way home from the airport, I called my sister. Three calls dropped in succession. This happened as I was driving on I-90 by Spokane, WA.

I don’t need Russian hackers to make my iPhone experience bad.


8 posted on 01/15/2024 8:10:36 AM PST by ProtectOurFreedom (“Occupy your mind with good thoughts or your enemy will fill them with bad ones.” ~ Thomas More)
[ Post Reply | Private Reply | To 4 | View Replies]

To: FarCenter
interesting comments at the link!

My take:
This attachment exploits the remote code execution vulnerability CVE-2023-41990 in the undocumented, Apple-only ADJUST TrueType font BACKDOOR instruction.
9 posted on 01/15/2024 8:11:31 AM PST by Mr Radical (In times of universal deceit, telling the truth is a revolutionary act.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: glorgau

I just updated to 17.2.1


10 posted on 01/15/2024 8:16:49 AM PST by null and void (I identify as a conspiracy theorist. My personal pronouns are told/you/so.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: ProtectOurFreedom

I have an iPhone 12 on Verizon. I haven’t had any such problems. Neither has my wife on her iPhone 13.


11 posted on 01/15/2024 8:18:28 AM PST by gitmo (If your theology doesn't match your biography, what good is it?)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Brian Griffin

I think there’s an option you can choose to not have updates on cell use time. IOW, only update when wifi is available, IIRC.


12 posted on 01/15/2024 8:20:50 AM PST by Gaffer
[ Post Reply | Private Reply | To 6 | View Replies]

To: gitmo

Again fingering T-Mobile. Things were good on Verizon for us and turned to crap when we switched. But saving 50% on our mobile bill is just too enticing.


13 posted on 01/15/2024 8:25:16 AM PST by ProtectOurFreedom (“Occupy your mind with good thoughts or your enemy will fill them with bad ones.” ~ Thomas More)
[ Post Reply | Private Reply | To 11 | View Replies]

To: ncfool

> I wonder if that is why my Apple iPhone 14 Pro is a piece of junk.

Get rid of tik-tok, facebook, and all the google stuff that you can live without. Those apps monitor everything and are resource hogs.

Basically, remove the mass marketing social media junk.


14 posted on 01/15/2024 8:40:52 AM PST by glorgau
[ Post Reply | Private Reply | To 4 | View Replies]

To: ncfool

I’m about a year into my iPhone 14 Pro, so far so good. From what you describe it sounds like the network used might be the issue. I’d talk to your carrier, and from there talk warranty with Apple. Good luck.


15 posted on 01/15/2024 8:57:18 AM PST by Made In The USA (Ellen Ate Dynamite Good Bye Ellen)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ProtectOurFreedom

We cut our mobile bill in half by switching from Verizon to T-Mobile and that is exactly when the problems started ... I don’t need Russian hackers to make my iPhone experience bad.


Its a carrier problem obviously, not an iPhone problem. Try a different carrier.


16 posted on 01/15/2024 9:16:53 AM PST by PIF (They came for me and mine ... now its your turn)
[ Post Reply | Private Reply | To 8 | View Replies]

To: PIF

I’ve talked to T-Mobile several times. They make some back-end changes and things get better for a while. Then the problems start again. I keep meaning to find another carrier that doesn’t operate on the T-Mobile network. Just haven’t had time.


17 posted on 01/15/2024 9:26:13 AM PST by ProtectOurFreedom (“Occupy your mind with good thoughts or your enemy will fill them with bad ones.” ~ Thomas More)
[ Post Reply | Private Reply | To 16 | View Replies]

To: FarCenter

Schneier is a good source. He doesn’t hype things up. Will be interesting to see his whole take on this. The first book I ever bought about crypto was his “Applied Cryptography”.


18 posted on 01/15/2024 9:28:41 AM PST by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ProtectOurFreedom

try spectrum


19 posted on 01/15/2024 9:31:48 AM PST by PIF (They came for me and mine ... now its your turn)
[ Post Reply | Private Reply | To 17 | View Replies]

To: PIF

Thanks. We have Spectrum Internet in Idaho.


20 posted on 01/15/2024 9:43:50 AM PST by ProtectOurFreedom (“Occupy your mind with good thoughts or your enemy will fill them with bad ones.” ~ Thomas More)
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-37 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson