Team OS : Your Only Destination To Custom OS !!

Welcome to TeamOS Community, Register or Login to the Community to Download Torrents, Get Access to Shoutbox, Post Replies, Use Search Engine and many more features. Register Today!

Tech News Most Sophisticated Apple iPhone Spyware Hack - Ever Exploited!

QL2l4g.jpeg

The spyware attacks targeting Apple iOS devices leveraged never-before-seen exploits that made it possible to even bypass pivotal hardware-based security protections erected by the company.

Russian cybersecurity firm Kaspersky, which the at the beginning of 2023 after becoming one of the targets, it as the "most sophisticated attack chain" it has ever observed to date. The campaign is believed to have been active since 2019.

The exploitation activity involved the use of four zero-day flaws that were fashioned into a chain to obtain an unprecedented level of access and backdoor target devices running iOS versions up to iOS 16.2 with the ultimate goal of gathering sensitive information.

The starting point of the zero-click attack is an iMessage bearing a malicious attachment, which is automatically processed sans any user interaction to ultimately obtain elevated permissions and deploy a spyware module. Specifically, it involves the weaponization of the following vulnerabilities -

  • CVE-2023-41990 - A flaw in the FontParser component that could lead to arbitrary code execution when processing a specially crafted font file, which is sent via iMessage. (Addressed in and )
  • - An integer overflow vulnerability in the Kernel that could be exploited by a malicious app to execute arbitrary code with kernel privileges. (Addressed in iOS 15.7.7, iOS 15.8, and iOS 16.5.1 )
  • - A memory corruption vulnerability in WebKit that could lead to arbitrary code execution when processing specially crafted web content. (Addressed in iOS 15.7.7 and iOS 16.5.1)
  • - An issue in the kernel that permits a malicious app to modify sensitive kernel state. (Addressed in iOS 16.6)
It's worth noting that patches for CVE-2023-41990 were released by Apple in January 2023, although details about the exploitation were only made public by the company on September 8, 2023, the same day it to resolve two other flaws (CVE-2023-41061 and CVE-2023-41064) that were actively abused in connection with a Pegasus spyware campaign.

This also brings the tally of the resolved by Apple since the start of the year to 20.

Of the four vulnerabilities, CVE-2023-38606 deserves a special mention as it facilitates a bypass of hardware-based security protection for sensitive regions of the kernel memory by leveraging memory-mapped I/O ( ) registers, a feature that was never known or documented until now.

The exploit, in particular, targets Apple A12-A16 Bionic SoCs, singling out unknown MMIO blocks of registers that belong to the GPU coprocessor. It's currently not known how the mysterious threat actors behind the operation learned about its existence. Also unclear is whether it was developed by Apple or it's a third-party component like ARM CoreSight.

To put it in another way, CVE-2023-38606 is the crucial link in the exploit chain that's closely intertwined with the success of the Operation Triangulation campaign, given the fact that it permits the threat actor to gain total control of the compromised system.

"Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake," security researcher Boris Larin said. "Because this feature is not used by the firmware, we have no idea how attackers would know how to use it."

"Hardware security very often relies on 'security through obscurity,' and it is much more difficult to reverse-engineer than software, but this is a flawed approach, because sooner or later, all secrets are revealed. Systems that rely on "security through obscurity" can never be truly secure."

The development comes as the Washington Post that Apple's warnings in about Indian journalists and opposition politicians may have been targeted by state-sponsored spyware attacks prompted the government to question the veracity of the claims and describe them as a case of "algorithmic malfunction" within the tech giant's systems.

In addition, senior administration officials demanded that the company soften the political impact of the and pressed the company to provide alternative explanations as to why the warnings may have been sent. So far, India has neither confirmed nor denied using spyware such as those by NSO Group's Pegasus.

Citing people with knowledge of the matter, the Washington Post noted that "Indian officials asked Apple to withdraw the warnings and say it had made a mistake," and that "Apple India's corporate communications executives began privately asking Indian technology journalists to emphasize in their stories that Apple's warnings could be false alarms" to shift the spotlight away from the government.

From:
 

Twistty

✅ Verified Member
Member
Downloaded
20.4 GB
Uploaded
7.4 TB
Ratio
372.01
Seedbonus
85,848
Upload Count
0 (0)
Member for 8 years
"algorithmic malfunction"
Almost as funny as "loot boxes" - "surprise mechanics". :oops:
 

SnowMonkey

✅ Verified Member
Member
Downloaded
248.2 GB
Uploaded
76.6 TB
Ratio
316.01
Seedbonus
1,063,219
Upload Count
0 (0)
Member for 2 years
"algorithmic malfunction"
Almost as funny as "loot boxes" - "surprise mechanics". :oops:

Wow...just wow...:banghead:

OT, is the sig pic a Skylark or Malibu?
 

Twistty

✅ Verified Member
Member
Downloaded
20.4 GB
Uploaded
7.4 TB
Ratio
372.01
Seedbonus
85,848
Upload Count
0 (0)
Member for 8 years

SnowMonkey

Good eye - It's a 68/69 Skylark (69 Frame - 68/69 body mods) with a 76 Buick - 455cid, o/b to 458cid with oversized valves (race heads) and an injection intake - and a "possy" rear-end.
Built that in early 2000's with my dad - over many years.
Not sure what it is worth today?
(Still have the "bills" from back then though).

I have a 65 Skylark also.
QLBPlR.jpeg

Was going to hopefully buy the 69 "Judge" convertible from my dad - til he told me the price.
Decided to build 2 cars instead. Lol :D
 
Last edited:

SnowMonkey

✅ Verified Member
Member
Downloaded
248.2 GB
Uploaded
76.6 TB
Ratio
316.01
Seedbonus
1,063,219
Upload Count
0 (0)
Member for 2 years

SnowMonkey

Good eye - It's a 68/69 Skylark (69 Frame - 68/69 body mods) with a 76 Buick - 455cid, o/b to 458cid with oversized valves (race heads) and an injection intake - and a "possy" rear-end.
Built that in early 2000's with my dad - over many years.
Not sure what it is worth today?
(Still have the "bills" from back then though).

I have a 65 Skylark also.
QLBPlR.jpeg

Was going to hopefully buy the 69 "Judge" convertible from my dad - til he told me the price.
Decided to build 2 cars instead. Lol :D
WOW!!! Love the mods. Nice whip my Man!
Had a used 70 Skylark back in the school days. You could bury the pedal and watch the gas gauge drop :rofl:
Yea, any of the really unique muscle cars, Daytona, Super Bee, Hurst Olds, etc., are crazy money nowadays.
 

vdogeek

🤴 Super Admin
Uploader
Downloaded
93.5 GB
Uploaded
56.5 TB
Ratio
619.16
Seedbonus
8,766,428
Upload Count
1199 (1205)
Member for 9 years

SnowMonkey

Good eye - It's a 68/69 Skylark (69 Frame - 68/69 body mods) with a 76 Buick - 455cid, o/b to 458cid with oversized valves (race heads) and an injection intake - and a "possy" rear-end.
Built that in early 2000's with my dad - over many years.
Not sure what it is worth today?
(Still have the "bills" from back then though).

I have a 65 Skylark also.
QLBPlR.jpeg

Was going to hopefully buy the 69 "Judge" convertible from my dad - til he told me the price.
Decided to build 2 cars instead. Lol :D
I had that same year Skylark but mine was blue ... loved it!
 

Toxined

✅ Verified Member
Member
Downloaded
20 GB
Uploaded
101.5 GB
Ratio
5.08
Seedbonus
55,506
Upload Count
0 (0)
Member for 7 years
Is this about a spyware or car techs... LOL... (Just kidding)
Nice car for sure. :h:(SuperBoy)
 
Top