You Can't Spell WebRTC Without RCE – Part 1
margin.re
margin.re
A messaging app has almost all the same security concerns as a browser, so the recommendations here apply: https://developer.apple.com/documentation/browserenginekit
I found no way to sandbox things beyond the sandboxes provided by iOS extension points (which are mostly XPC under the hood, but with no control options for the app).
Apple makes heavy use of XPC to sandbox iMessage services, but on iOS that remains an Apple-only feature.
I assume Signal uses a different implementation, but I'm sadly not surprised there are security issues lurking inside it.
This bit at the beginning made me chuckle, though:
> It’s another average Friday morning and my iPhone shows 705 unread Signal messages
I feel like I'm doing communications wrong... if I wake up and find 20 unread messages across all my chat apps, that's on the high side for me.
Regardless, I think a handful of high quality meaningful messages is well worth hundreds of low value ones.
e.g. “Given a vulnerability, this is what crafting an exploit looks like”
So, it is a build instruction.
They took Signal-webrtc & added a vulnerability to it.
Maybe maybe maybe there's some other means to exploit the lack of time check, but this feels like such a massive & overwhelmingly staked out nothing burger.
They’re usually known for high quality research, not fluff like this…