Apple

Apple Leverages Zero-click Attacks Via Messages In iOS

The introduction of the new technology called “BlastDoor” has been quietly implemented by Apple. However, it is deeply anchored in iOS 14, so that it can be assumed that the company simply did not want to talk about the matter in greater detail – especially not at the official presentation of the new operating system version. Discovered was the matter of security researcher Samuel Gross, who is responsible for Google Project Zero for iPhone exploits and attacks via Messenger.

So-called zero-click attacks via message services have been a popular attack vector for some time. All that is needed here is an unpatched vulnerability in the messenger to gain access to the system. This method is usually more suitable than a similar attempt via e-mail since messengers are active on significantly more smartphones at shorter intervals and thus malware can spread more efficiently.

New hurdles on many levels

However, as a rule, entire chains of the exploit are required that exploit several vulnerabilities in combination in order to be successful. Most of the time, the attacks run via insecure memory areas, through which malicious code can then be smuggled into the system without the need for interaction with the user or a message from the system.

Read More: Apple Mail Vulnerabilities Found Could Lead To Attacks On iPhone Users

And BlastDoor puts a pretty heavy stop to that. Incoming iMessage messages are subjected to a multi-stage check by the technology. In addition, Apple integrates procedures that can better identify problematic storage areas and place them under special observation. The main aim here is to prevent new brute force attempts to circumvent Address Space Layout Randomization (ASLR) from being intercepted.

According to Grob, however, BlastDoor makes all levels that normally belong to zero-click attacks much more difficult. Attackers not only have to overcome an additional hurdle here, but they also have to penetrate a whole network of new protective measures. The security researcher certifies that Apple is using what is probably the best method that is possible if you also have to consider things like downward compatibility.

Recent Posts

Mouse for MMO players: Razer’s new Naga V3 Pro is a button monster

Razer is launching a new MMO mouse with the Naga V3 Pro. Three magnetic side…

9 hours ago

Surface Phone: New images show discarded Microsoft prototype

It's an open secret that Microsoft was working on a Windows Phone smartphone long before…

9 hours ago

How Solar Carport Structures Are Changing the Future of Sustainable Energy Infrastructure

As the demand for renewable energy continues to grow, businesses, municipalities, and property owners are…

10 hours ago

What to do to find the right family law support in your case.

Family law issues seldom come at an opportune moment. Divorce, separation, parenting conflicts, child support,…

10 hours ago

Claude AI data leak: Private chats were freely accessible on Google

Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…

1 day ago

Mark Zuckerberg’s megayacht Launchpad ignored calls for help off Alaska

Mark Zuckerberg's $300 million superyacht ignored or allegedly did not hear a call for help…

1 day ago