At the end of the day, it is still an app with app level permissions, sandbox etc.
Kernel\Kernel modules are far more likely to be written as they allow for vastly more access than an app.
At the end of the day, it is still an app with app level permissions, sandbox etc.
Kernel\Kernel modules are far more likely to be written as they allow for vastly more access than an app.
Reasons for worry about the baseband code:
a) Code is written by a third parties
b) Apple is more restricted applying defence-in-depth (customised security CPU changes like PAC, customised compiler changes, etcetera).
c) harder to detect intrusion?
Versus reasons not to worry so much:
z) Baseband has more limited access to information
y) harder to make exploit survive a reboot - mainly useful as part of chain of exploit into main CPU?
x) Baseband code is device specific - helps to know target device to attack
you can pretty much access whatever you want.
You don't need to access the messages app in order to get access to the messages.
it's the opposite actually, the messaging app needs permissions for the system level messaging component.
you're already root.
you can access any component without much restriction.
How the data is stored has nothing to do with this
Pwning the app will only provide access to whatever permission it has and we are still sandboxed.
Pwning a kernel module\driver will provide access to everything whether its messaging, call logs, pictures etc. we are not sandboxed, we don't need an LPE exploit.
I think the priority is clear.