HNHacker News
TopNewBestAskShowJobs

illusionofchaos

32 karma · joined September 24, 2021

submissionscomments
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
I've updated the article to include a timeline for each vulnerability
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
It can be shipped, static analysis is easily bypassed, you can check it yourself on gamed exploit
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
Good idea, I've added the comment
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
Look at the code of gamed exploit that I've uploaded to GitHub, the app is written in Swift and it calls Objective-C runtime functions from it
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
If you have a developer account that you are willing to sacrifice and don't mind the possibility of legal action, you can try that. I've managed to upload the binary built from the source code from gamed exploit repository on GitHub to App Store Connect and installed it onto my own device via TestFlight. I didn't submit it for review, but if the functionality would have been concealed, it would easily pass.

As far as I know, how the review happens is that reviewers just install apps onto their iPads, tap through all the screens they can find and make their decisions based purely on that. So if an app connects to server and asks what it should do, it's possible to make an app behave differently for reviewers and all other users.

illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
It's just marked as unavailable. Apple does that to try keeping people from using XPC on iOS. Use the full code from GitHub, it has a bypass for that Xcode check
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
I haven't checked further, maybe authentication token can be used to gain access to Apple account and more data. Also one other method could used to write arbitrary data outside of an app sandbox, that might be useful for further exploitation.
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
You can see the logs in JSON inside Settings app. Also if two vulnerabilities are used together, you can get full name and email and connect it to health data
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
That's exactly how it happened for me. I noticed that when an app logs into Game Center, the notification is shown inside the app, and not in a remote process like when you choose contacts of compose an email. That led to easily discovering everything else.
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
> static analysis which Apple obviously uses as part of its approval process

This analysis is a joke, it just scans strings inside binaries against the list of symbols corresponding to what Apple considers to be Private API. Gamed exploit can be uploaded to the App Store and binary will pass their analysis with flying colors

illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
Furthermore, no one stops you from developing an app and planting RCE vulnerability inside the binary. Then you can exploit it remotely when necessary and execute the code that exploits any iOS vulnerabilities known to you.
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
Zerodium is not interested in this kind of bugs. If they own at least one RCE+LPE, they can already access all data on any device and more
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
This is just a check built into Xcode to try to keep you from accessing XPC in iOS. The code on GitHub bypasses this by calling this method dynamically through Objective-C runtime
illusionofchaos··on Disclosure of three 0-day iOS vulnerabilities
Follow the links to GitHub, the code there compiles perfectly, the PoC inside the article is just a shortened version