Skip to main content

Apple iOS 14 introduces BlastDoor Sandbox security system to iMessage

In the past, there have been various instances where security researchers revealed that a “string of texts” received over SMS could crash your phone or worse, send it into a boot-loop. These kinds of exploits have been reported at least once every year for both iOS and Android smartphones but turns out, iOS 14 has a way to thwarting these kinds of exploits for good, thanks to a system called BlastDoor.

Discovered by a Google Project Zero researched named Samuel Groß, BlastDoor works by parsing all the data contained in an iMessage in a secure sandbox, isolated from the rest of the operating system. By doing so, the contents of the iMessage, if nefarious, won’t have an impact on the OS. All apps installed on an iOS device exist in their own sandboxes, which governed by very tight policies. The BlastDoor sandbox for iMessage has been designed to thwart most exploits which either use brute force or exploit the shared cache on iOS.  Groß says he found the existence of BlastDoor when investigating a hacking campaign against Al Jazeera journalists. There were instances where the hacks did not work and the common thread appeared to be the fact that they were running iOS 14 on their iPhones.

While BlastDoor sandbox definitely makes iMessage more secure, it does not do much for the traditional SMS. Last year in April 2020, a text-based exploit was discovered which could be initiated via a normal SMS. A string of characters written in Sindhi when received as an SMS would freeze iOS completely, rendering the person’s iPhone/iPad completely useless till the OS would crash, and the device could be rebooted. This was due to a bug in iOS, one which Apple has since fixed, but it highlights how the short messaging service format is still a likely vector for delivering exploits.

Messaging apps have been a popular point of intrusion into smartphones for several years now. We’ve seen text message string crash phones, brick them permanently, lock them temporarily, and in one case, even serve as a means of gaining full access to the device. The now infamous Pegasus used a vulnerability in WhatsApp, allowing the hacker full access to a target smartphone, all done remotely. The BlastDoor sandbox for iMessage introduced in iOS14 should prevent some, if not all intrusion and malicious events.



from Latest Technology News https://ift.tt/36nuZin

Comments

Popular posts from this blog

PS5 unboxing videos show how huge the console is

To say that Sony has been a bit coy when it comes to the PlayStation 5 would be a bit of an understatement. The company only recently announced the India pricing of the console and now finally we have unboxings of the console going live and one thing is pretty clear - The console is HUGE!  So what do you get in the box? Well… besides the console itself (and the manuals), you get: DualSense controller USB Type-C charging cable for the controller HDMI 2.1 cable Power cable for the console (no bulky adapter/box) Plastic stand Now the plastic stand is used if you place the console on its side. As there is no flat surface on either side of the console, the stand will ensure that it remains still. But you can also place it when propping up the console vertically. However, it does seem like the PS5 can stand on its own vertically if need be. IGN’s unboxing video gives you a good idea of how to place the stand. All of the unboxing videos mention the size of the console because it is pr...

Pixel 4a (5G) Model Tipped in Google Camera v7.5 App Code, Pixel 5 XL May Not Launch This Year: Report

Google Camera app version 7.5 teardown, rolled out for Android 11 beta users, shows mentions of three upcoming Pixel devices - Pixel 4a, Pixel 4a (5G), and Pixel 5, with no reference to the Pixel 5 XL. This hints that Google may be ditching the Pixel 5 XL this year. The codenames of the three upcoming Pixel devices are listed to be sunfish, bramble... from Gadgets 360 https://ift.tt/3gd9bJp