73 points

Couldn’t think of a better title, TL;DR via receiving an iMessage with a specially crafted image, an attacker can get full access to your device. Update iOS immediately to resolve the issue

permalink
report
reply
35 points

PSA: Android just published a patch for a very similar vulnerability in their September Security release. You should update your Android devices ASAP.

permalink
report
parent
reply

Which CVE is that and where can i read a description of how this vulnerability is being used?

permalink
report
parent
reply
6 points

CVE-2023-35674 No real details published yet but Google discussed it in their September security bulletin.

permalink
report
parent
reply
-71 points
*
Deleted by creator
permalink
report
parent
reply
50 points
*

Get off that high horse.

permalink
report
parent
reply
20 points

How do you block MMS from unknown senders on iOS?

permalink
report
parent
reply
6 points

Settings > Messages > SMS/MMS > MMS Messaging (uncheck)

And/Or

Message Filtering > Filter Unknown Senders (checked)

Those seem to be the likely options, but I’ve zero idea if those will work.

permalink
report
parent
reply
-1 points
*
Deleted by creator
permalink
report
parent
reply
12 points
*

at this point most iphone users are very much used to reicive images within imessage and have already forgotten that mms existed or are too young to actually ever had to deal with it, so to them it’s just yet another picture.

permalink
report
parent
reply
-4 points
*
Deleted by creator
permalink
report
parent
reply
5 points

I’d never get random dick pictures that way though.

permalink
report
parent
reply
18 points

Damn…so this isn’t the fun kernel level access exploit.

This is the boring, my data could be compromised exploit.

permalink
report
reply
11 points

Fuck, the NSO group managed that shit again?!

permalink
report
reply
9 points

lmao, iMessage again ? zero user interaction needed, again ?!

Well done Apple

permalink
report
reply
32 points
*

It’s literally been 3 days since Android had a vulnerability of this exact nature: remote code execution with zero user interaction required (CVE-2023-35674).

Every piece of software has vulnerabilities lurking within. What matters is the velocity at which vendors address and resolve those vulnerabilities. Apple and Google are both exemplary at getting patches out quickly.

permalink
report
parent
reply
15 points

Stop bringing up old news. We’re hating on Apple today!

permalink
report
parent
reply
2 points

Oops! I forgot to check the schedule.

permalink
report
parent
reply
0 points

Every piece of software has vulnerabilities lurking within.

Remind me why we put up with this again? Formal verification does exist.

permalink
report
parent
reply
3 points

Formal Verification doesn’t guarantee that the code is free of vulnerability, it just increases confidence in its security. It’s never perfect.

permalink
report
parent
reply
6 points

butbutbut… blue box

permalink
report
parent
reply
7 points
*

Article missing, here is the archive link. https://web.archive.org/web/20230908134811/https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/

Edit: able to access now but I’ll leave it here just in case.

permalink
report
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 4.6K

    Monthly active users

  • 2.9K

    Posts

  • 77K

    Comments