home.social

#phones — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #phones, aggregated by home.social.

  1. “The U.S. Department of Defense has disabled advertising #tracking on troops’ #phones and #computers as part of an effort to protect them from threats that target their #locations, according to a letter shared with Senator Ron Wyden.” #US
    techcrunch.com/2026/09/04/us-m

  2. “The U.S. Department of Defense has disabled advertising #tracking on troops’ #phones and #computers as part of an effort to protect them from threats that target their #locations, according to a letter shared with Senator Ron Wyden.” #US
    techcrunch.com/2026/09/04/us-m

  3. “The U.S. Department of Defense has disabled advertising #tracking on troops’ #phones and #computers as part of an effort to protect them from threats that target their #locations, according to a letter shared with Senator Ron Wyden.” #US
    techcrunch.com/2026/09/04/us-m

  4. “The U.S. Department of Defense has disabled advertising #tracking on troops’ #phones and #computers as part of an effort to protect them from threats that target their #locations, according to a letter shared with Senator Ron Wyden.” #US
    techcrunch.com/2026/09/04/us-m

  5. “The U.S. Department of Defense has disabled advertising #tracking on troops’ #phones and #computers as part of an effort to protect them from threats that target their #locations, according to a letter shared with Senator Ron Wyden.” #US
    techcrunch.com/2026/09/04/us-m

  6. disabled tracking on troops’ devices following reports of targeted attacks
    This includes the departments’ iPhones and Android devices, and Windows computers managed across the federal military enterprise network, the letter said.
    The aim is to prevent adversaries, including hostile governments, from using data derived from apps on troops’ to target them on battlefield or on base.
    techcrunch.com/2026/09/04/us-m
    archive.ph/19yfV
    YOU should have an !

  7. #US #military disabled #ad tracking on troops’ devices following reports of targeted attacks
    This includes the departments’ iPhones and Android devices, and Windows computers managed across the federal military enterprise network, the letter said.
    The aim is to prevent adversaries, including hostile governments, from using #location data derived from apps on troops’ #phones to target them on battlefield or on base.
    techcrunch.com/2026/09/04/us-m
    archive.ph/19yfV
    YOU should have an #adblocker!

  8. #US #military disabled #ad tracking on troops’ devices following reports of targeted attacks
    This includes the departments’ iPhones and Android devices, and Windows computers managed across the federal military enterprise network, the letter said.
    The aim is to prevent adversaries, including hostile governments, from using #location data derived from apps on troops’ #phones to target them on battlefield or on base.
    techcrunch.com/2026/09/04/us-m
    archive.ph/19yfV
    YOU should have an #adblocker!

  9. #US #military disabled #ad tracking on troops’ devices following reports of targeted attacks
    This includes the departments’ iPhones and Android devices, and Windows computers managed across the federal military enterprise network, the letter said.
    The aim is to prevent adversaries, including hostile governments, from using #location data derived from apps on troops’ #phones to target them on battlefield or on base.
    techcrunch.com/2026/09/04/us-m
    archive.ph/19yfV
    YOU should have an #adblocker!

  10. #US #military disabled #ad tracking on troops’ devices following reports of targeted attacks
    This includes the departments’ iPhones and Android devices, and Windows computers managed across the federal military enterprise network, the letter said.
    The aim is to prevent adversaries, including hostile governments, from using #location data derived from apps on troops’ #phones to target them on battlefield or on base.
    techcrunch.com/2026/09/04/us-m
    archive.ph/19yfV
    YOU should have an #adblocker!

  11. В продовження теми шкідливого ПЗ. Ось, дуже прошу. Компрометація iPhone через дірявий додаток iMessage з 0 кліків - тобто від користувача вимагається нуль дій (zero-click/zero-touch attack). Так що, Айфон - не панацея!

    Убивчий ланцюжок (Cyber Kill Chain) виглядає наступним чином (почерпнуто і перекладено з французької в дослідника Фреда Райналя з Quarkslab, Париж):

    ➡️ Зловмисник надсилає PDF-файл в iMessage, який додаток обробляє, не показуючи його користувачеві

    ➡️ Зловмисник використовує нестандартну та недокументовану команду ADJUST для шрифтів True Type. Вразливість існує вже 19 років. Патч CVE-2023-41990 вилучає її.

    ➡️ Корисне навантаження написано на ROP/JOP для маніпулювання внутрішніми об'єктами Apple, маніпулювання бібліотекою JavaScriptCore, а потім ініціювання підвищення привілеїв, написаних на JavaScript.

    ➡️ Експлойт дуже заплутаний, вміщується в 11000 рядків коду (це дуже багато). В основному він спрямований на JavaScriptCore та обробку областей пам'яті ядра. Він націлений на налагоджувальну функцію DollarVM ($vm). Він маніпулює пам'яттю скрипта та отримує доступ до нативних API.

    ➡️ Він містить механізм обходу коду автентифікації покажчика (PAC), наявного в A12, механізм, призначений для захисту від використання пошкодження пам'яті.

    ➡️ Він використовує цілочисельне переповнення (CVE-2023-32434) у функціях відображення пам'яті ядра XNU для читання/запису всієї фізичної пам'яті телефону з простору користувача.

    ➡️ Він використовує недокументовані регістри зіставлення пам'яті (MMIO) SoC iPhone, щоб обійти рівень захисту сторінок (PPL) CVE-2023-38606. Цей механізм запобігає зміні сторінок пам'яті після їх підписання.

    ➡️ Експлойт JavaScript отримує повний контроль над телефоном. Нападник запускає:
    (1) Процес, який очищає всі сліди на пристрої (зокрема PDF-файл)
    (2) Браузер Safari невидимий на вибраній вами вебсторінці

    ➡️ Веб-сторінка має JavaScript, вбудований у JavaScript, який запускає купу додаткових елементів керування на пристрої перед запуском експлойта, націленого на Safari.

    ➡️ Експлойт використовує вразливість CVE-2023-32435, а потім запускає своє корисне навантаження

    ➡️ Корисне навантаження повторно використовує вразливості CVE-2023-32434 і CVE-2023-38606, але безпосередньо з об'єкта ядра (Mach). Той же принцип, розбір пам'яті і тотальна компрометація системи в кінцевому підсумку.

    ➡️ Зловмисник завантажує та встановлює свій руткіт.

    💰Важливі особливості:
    ✔️ 0 кліків: жодних дій збоку власника
    ✔️ Експлуатуються 4 вразливості нульового дня (0-Zero-Day), які ще не були виправлені виробником, включаючи непублічні функції, які на 100% працюють з обходом PAC і PPL
    ✔️ Працює до версії iOS 16.2
    ✔️ Вартість експлойту: $5 млн

    #exploitation #imessage #iphone #hacking #ios #ios16 #malware #ransomware #exploit #mobilesecurity #infosec #cybersecurity #phones #messengers #rootkit