Apple

Apple Leverages Zero-click Attacks Via Messages In iOS

The introduction of the new technology called “BlastDoor” has been quietly implemented by Apple. However, it is deeply anchored in iOS 14, so that it can be assumed that the company simply did not want to talk about the matter in greater detail – especially not at the official presentation of the new operating system version. Discovered was the matter of security researcher Samuel Gross, who is responsible for Google Project Zero for iPhone exploits and attacks via Messenger.

So-called zero-click attacks via message services have been a popular attack vector for some time. All that is needed here is an unpatched vulnerability in the messenger to gain access to the system. This method is usually more suitable than a similar attempt via e-mail since messengers are active on significantly more smartphones at shorter intervals and thus malware can spread more efficiently.

New hurdles on many levels

However, as a rule, entire chains of the exploit are required that exploit several vulnerabilities in combination in order to be successful. Most of the time, the attacks run via insecure memory areas, through which malicious code can then be smuggled into the system without the need for interaction with the user or a message from the system.

Read More: Apple Mail Vulnerabilities Found Could Lead To Attacks On iPhone Users

And BlastDoor puts a pretty heavy stop to that. Incoming iMessage messages are subjected to a multi-stage check by the technology. In addition, Apple integrates procedures that can better identify problematic storage areas and place them under special observation. The main aim here is to prevent new brute force attempts to circumvent Address Space Layout Randomization (ASLR) from being intercepted.

According to Grob, however, BlastDoor makes all levels that normally belong to zero-click attacks much more difficult. Attackers not only have to overcome an additional hurdle here, but they also have to penetrate a whole network of new protective measures. The security researcher certifies that Apple is using what is probably the best method that is possible if you also have to consider things like downward compatibility.

Recent Posts

Navigating the Digital Frontier: How Mobile Proxy Infrastructure Empowers Modern Technology Journalism and Enterprise Data Mining

For tech analysts, software engineers, and digital journalists tracking real-time market shifts on platforms like…

21 hours ago

Decoupling Digital Identity: How Modern App Ecosystems Rely on Virtual Telecommunications Architecture

Modern mobile security models treat phone numbers as default digital passports, forcing tech consumers and…

21 hours ago

Top Extended Detection and Response Platforms for Large Enterprises: A Vendor Comparison Guide

Large enterprises have a lot of security data, but identifying the signals that truly matter…

22 hours ago

5 Lab Methods Scientists Use to Find What’s Really in Tap Water

A glass of tap water reveals little about its chemical makeup. Clear water may still…

2 days ago

Medical Technology Leadership Programs and Industry Collaborators: The Essential Resource Roundup

In today’s healthcare landscape, collaboration between academic programs and corporate leaders fuels both technological innovation…

3 days ago

Smartphone ban: Italy will soon pay for distracted pedestrians

Italy is cracking down on cell phone use in traffic and will soon be targeting…

3 days ago