Security News > 2020 > January > Google Researchers Detail Critical iMessage Vulnerability

Google Project Zero security researchers have published technical details on an iMessage vulnerability addressed last year, which could be exploited remotely to achieve arbitrary code execution.
Tracked as CVE-2019-8641, the vulnerability is considered Critical, featuring a CVSS score of 9.8, and was discovered by Google Project Zero security researchers Samuel Groß and Natalie Silvanovich.
The remote attack surface includes the iMessage data format and the NSKeyedUnarchiver API, which can be triggered both sandboxed and unsandboxed.
To address the flaw, Apple first made the vulnerable code unreachable over iMessage, but then fully addressed the vulnerability in subsequent updates.
In a talk a SecurityWeek's 2019 CISO Forum, Presented by Intel, Silvanovich discussed Project Zero's research into iMessage and their research methodology, along with what there is to learn from vulnerabilities in commonly-used software.
News URL
Related news
- Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution (source)
- Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices (source)
- Google OAuth Vulnerability Exposes Millions via Failed Startup Domains (source)
- Google Cloud Researchers Uncover Flaws in Rsync File Synchronization Tool (source)
- Researcher Uncovers Critical Flaws in Multiple Versions of Ivanti Endpoint Manager (source)
- Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw (source)
- Zyxel CPE devices under attack via critical vulnerability without a patch (CVE-2024-40891) (source)
- Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score (source)
- Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability (source)
- Twin Google flaws allowed researcher to get from YouTube ID to Gmail address in a few easy steps (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-12-18 | CVE-2019-8641 | Out-of-bounds Read vulnerability in Apple products An out-of-bounds read was addressed with improved input validation. | 9.8 |