QualPwn – Exploiting Qualcomm WLAN and Modem over the Air
blade.tencent.com
blade.tencent.com
This seems big and unprecedented. Layperson in this area, so...am I wrong?
It's only in relatively recent times that shared memory interfaces have fallen under the security spotlight as new scenarios arise where a trusted driver may not be speaking to a trusted piece of hardware (e.g. virtualization), so there are plenty of attacks around that involve hopping across an interface assumed to have been free of trust boundaries (Firewire is another example kinda like this)
It's bad, but it's absolutely not unprecedented. The first time a similar issue was discovered was by Prozect Zero: https://googleprojectzero.blogspot.com/2017/04/over-air-expl... https://googleprojectzero.blogspot.com/2017/04/over-air-expl...
It has some pretty damning facts, including that most mobile devices have some form of IOMMU in theory, but they don't use it.
Later there was the Broadpwn vulnerability, which was very similar. I believe there were more of them later.