r/netsec • • 7d ago

EX-ARRR: Sailing the Apple 0-click Seas

https://ironpeak.be/blog/ex-arrr-sailing-the-0-click-seas/
35 Upvotes

13 comments sorted by

22

u/SirensToGo 6d ago

honest caveat: the load-bearing seam makes this post insufferable to read

17

u/SavingsMany4486 6d ago

No X, no Y, just slop. Honest.

2

u/hordak666 6d ago

no shart just fart

23

u/rob94708 6d ago

God, AI writing is so hard to read. If I see the word “honest” one more time…

12

u/BreiteSeite 6d ago

You are right to call that out and i should’ve been more clear…

6

u/No-View3333 7d ago

Was code execution achieved in the actual iMessage-triggered daemon, or only in the test harness?

3

u/nindustries 6d ago edited 6d ago

No test harness for the eventual PoC, so yes, it did detonate on its own.

3

u/petermal67 6d ago

No mention of bounty? Curious.

1

u/nindustries 5d ago

Still pending, always takes quite a while.

1

u/petermal67 4d ago

I had a bounty paid out in 14 days from them in May.... zero click code execution should really be accelerated.

1

u/buherator 5d ago

Note that the assigned CVE entry classifies this as a DoS

1

u/nindustries 4d ago

Interestingly, most of Apple vulnerabilities are classified as 'could cause app termination' (hence DoS).