WiFiDemon – iOS WiFi RCE 0-Day Vuln, and a Zero-Click Vuln That Was Patched
blog.zecops.com
blog.zecops.com
Is it wormable? That is, could a worm use it as a vector for spreading?
If I understood this article correctly, the answer in this case is probably YES. A worm could use this vulnerability to inject itself into a phone without any user intervention, and once there use the same vulnerability to attack other phones of the same model around it, recursively. Since the reach of a WiFi beacon is not short (it always uses the lowest speed, and IIRC can easily reach a hundred meters), on a dense metropolitan area with enough of the vulnerable device models, it could spread very quickly.
In other words, this vulnerability is of the "patch immediately, and if you can't, completely disconnect the device until it's patched" kind. I don't know much about iOS, but if this were Android, just disabling WiFi (without disabling a couple of hard-to-find settings related to location) wouldn't be enough; airplane mode might be enough, but for this class of device, would severely limit its main functionality.
Can anyone read the decompiled code in the screenshot? It seems like it does this:
x = stringWithFormat(const_string, attacker_string);
y = stringWithFormat(const_string2, x);
log(y);
Is that really exploitable or am I reading it wrong?I guess nobody here knows Objective-C so I'll never know how the latter attack works ¯\_(ツ)_/¯