Just to understand, what is the blast radius of this exploit?
Do they just have access to the whole process memory of the iMessage process?
Or does it go beyond that?
Do they just have access to the whole process memory of the iMessage process?
Or does it go beyond that?
The BlastDoor sandbox was added since then (which project zero also has a post on), but this exploit happened outside the blastdoor sandbox, so that doesn't change anything.
If previous iMessage exploits are anything to go on, it's likely this gives unsandboxed root access to all memory on the device.