Security News > 2020 > January > Google Researchers Detail Critical iMessage Vulnerability
Google Project Zero security researchers have published technical details on an iMessage vulnerability addressed last year, which could be exploited remotely to achieve arbitrary code execution.
Tracked as CVE-2019-8641, the vulnerability is considered Critical, featuring a CVSS score of 9.8, and was discovered by Google Project Zero security researchers Samuel Groß and Natalie Silvanovich.
The remote attack surface includes the iMessage data format and the NSKeyedUnarchiver API, which can be triggered both sandboxed and unsandboxed.
To address the flaw, Apple first made the vulnerable code unreachable over iMessage, but then fully addressed the vulnerability in subsequent updates.
In a talk a SecurityWeek's 2019 CISO Forum, Presented by Intel, Silvanovich discussed Project Zero's research into iMessage and their research methodology, along with what there is to learn from vulnerabilities in commonly-used software.
News URL
Related news
- Apple Releases Critical iOS and iPadOS Updates to Fix VoiceOver Password Vulnerability (source)
- Week in review: Critical Zimbra RCE vulnerability exploited, Patch Tuesday forecast (source)
- Experts Warn of Critical Unpatched Vulnerability in Linear eMerge E3 Systems (source)
- New Critical GitLab Vulnerability Could Allow Arbitrary CI/CD Pipeline Execution (source)
- Critical Veeam Vulnerability Exploited to Spread Akira and Fog Ransomware (source)
- Critical Kubernetes Image Builder Vulnerability Exposes Nodes to Root Access Risk (source)
- Fortinet releases patches for undisclosed critical FortiManager vulnerability (source)
- VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability (source)
- FortiManager critical vulnerability under active attack (source)
- Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-12-18 | CVE-2019-8641 | Out-of-bounds Read vulnerability in Apple products An out-of-bounds read was addressed with improved input validation. | 9.8 |