
Patrick Wardle
10.4K posts

Patrick Wardle
@patrickwardle
🛠 🍎 👾 Objective-See'ing & DoubleYou'ing







A second iOS exploit has been spotted in use by Russian spies to infect websites and hack visitors' iPhones. This one works on iOS 18, and appeared in a very reusable form, so will likely proliferate. If you haven't updated your iPhone, now's the time. wired.com/story/hundreds…








Lets talk about the privilege escalation from Coruna chain (iOS 16.6). As seen in the console after the infection, the power management daemon attempts to establish an internet connection. By this point, the PE has already been executed.



Apple: “3rd-party security tools can’t run in the kernel because they might panic.” Also Apple: kicks us out and replaces us with their EndpointSecurity kext ...which can be trivially panicked from userland, taking down every security tool + the whole system (macOS 26.3.1)! 🙄
















