Comment by snazz

3 years ago

Interesting that this exploit has continued to work through 15.7. Apple’s earlier BlastDoor system (introduced with iOS 14) clearly hasn’t done enough to stop future zero-click iMessage exploits, so I wonder what attack surface these bugs are found in. Does anyone have a more complete understanding of why the BlastDoor mitigation has been so insufficient?

AIUI they put a lot of the message parsing into its own tightly sandboxed process. That surely makes exploitation harder, but ultimately that process will have to communicate the results of parsing to other processes, and considering the huge diversity of things iMessage messages can do, there must still be a lot of vulnerable surface area?

Lock down mode blocks all SMS attachments. It's a bit annoying but a wonderful feature.