[HN Gopher] Operation Triangulation: iOS Security Issue
       ___________________________________________________________________
        
       Operation Triangulation: iOS Security Issue
        
       Author : fortran77
       Score  : 74 points
       Date   : 2023-06-01 14:07 UTC (8 hours ago)
        
 (HTM) web link (securelist.com)
 (TXT) w3m dump (securelist.com)
        
       | snazz wrote:
       | Interesting that this exploit has continued to work through 15.7.
       | Apple's earlier BlastDoor system (introduced with iOS 14) clearly
       | hasn't done enough to stop future zero-click iMessage exploits,
       | so I wonder what attack surface these bugs are found in. Does
       | anyone have a more complete understanding of why the BlastDoor
       | mitigation has been so insufficient?
        
         | TazeTSchnitzel wrote:
         | AIUI they put a lot of the message parsing into its own tightly
         | sandboxed process. That surely makes exploitation harder, but
         | ultimately that process will have to communicate the results of
         | parsing to other processes, and considering the huge diversity
         | of things iMessage messages can do, there must still be a lot
         | of vulnerable surface area?
        
       | chatmasta wrote:
       | > The malicious toolset does not support persistence, most likely
       | due to the limitations of the OS.
       | 
       | This is a reminder to reboot your device if you haven't in a
       | while. I have an app called iVerify, from Trail of Bits, which
       | sends me periodic notifications reminding me to reboot or upgrade
       | my OS.
        
       | walterbell wrote:
       | Can iMessage be disabled by MDM / Apple Configurator policy?
        
         | traceroute66 wrote:
         | > Can iMessage be disabled by MDM / Apple Configurator policy?
         | 
         | Yes to both.
         | 
         | Don't forget iOS 16 lockdown mode as well as a third option.
        
       | paywallasinbeer wrote:
       | So light on details that it's useless. Apparently, the actual
       | IoCs and details are here https://securelist.com/operation-
       | triangulation/109842/
        
       | blakesterz wrote:
       | I think that link is just a bit off, the report and details is
       | here
       | 
       | https://securelist.com/operation-triangulation/109842/
        
       | highwaylights wrote:
       | Would be interested to know if by 15.7 they mean that it's
       | currently a zero-day for 15.7.X devices, or if it's since been
       | patched in security updates. Also not clear if any 16.X software
       | is vulnerable.
       | 
       | Obviously not a good thing either way, but the most important
       | part of this from the user perspective is whether or not up-to-
       | date devices are vulnerable.
        
       | bwj982 wrote:
       | Does iOS lockdown mode mitigate this vulnerability?
        
         | galad87 wrote:
         | The article says the most recent version of iOS targeted is
         | 15.7, which don't have the lockdown mode (it was introduced in
         | iOS 16). There isn't any details on how the exploit works yet,
         | so it's hard to say.
        
           | bwj982 wrote:
           | Thank you, I missed that detail
        
       | mmastrac wrote:
       | Is this a PDF exploit?
       | 
       | > Data usage information of the services
       | com.apple.WebKit.WebContent,
       | powerd/com.apple.datausage.diagnostics,
       | lockdownd/com.apple.datausage.security
        
       ___________________________________________________________________
       (page generated 2023-06-01 23:02 UTC)