Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

The meek are contesting the will.


computers / comp.mobile.ipad / Older iOS devices are extremely vulnerable to this active iOS exploit

SubjectAuthor
o Older iOS devices are extremely vulnerable to this active iOS exploitSail Fisherman

1
Older iOS devices are extremely vulnerable to this active iOS exploit

<tqpqm8$2hpqf$1@paganini.bofh.team>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2707&group=comp.mobile.ipad#2707

  copy link   Newsgroups: misc.phone.mobile.iphone comp.mobile.ipad
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: sailfisherman@sailfisherman.com (Sail Fisherman)
Newsgroups: misc.phone.mobile.iphone,comp.mobile.ipad
Subject: Older iOS devices are extremely vulnerable to this active iOS exploit
Date: Wed, 25 Jan 2023 08:47:31 +0900
Organization: To protect and to server
Message-ID: <tqpqm8$2hpqf$1@paganini.bofh.team>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 24 Jan 2023 23:47:21 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="2680655"; posting-host="bLgAET+TqO1vMyaCrzDo2Q.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team"; posting-account="9dIQLXBM7WM9KzA+yjdR4A";
User-Agent: Thunderbird 2.0.0.24 (Windows/20100228)
Cancel-Lock: sha256:NEUVAQwhjBADiGcqo5m9YzaSIqujA65fk6krtVa9AbA=
X-Notice: Filtered by postfilter v. 0.9.3
 by: Sail Fisherman - Tue, 24 Jan 2023 23:47 UTC

Older iOS devices are seriously vulnerable to this active exploit.
The attackers have mostly pwned any iOS 12 device they could find.

Apple has issued an emergency patch for older kit to fix a WebKit security
flaw that Cupertino warns is under active attack.
https://www.theregister.com/2023/01/24/apple_iphone_bug_under_exploit/

On Monday, Apple released iOS 12.5.7 for iPhone 5s, iPhone 6, iPhone 6
Plus, iPad Air, iPad mini 2, iPad mini 3, and sixth-generation iPod touch.
It also updated iOS and iPadOS 15 and 16, but it appears that, at least as
of now, attackers are only going after devices running the very-old iOS 12.

If you have one of these older devices, we'd suggest updating to the new
iOS immediately as the vulnerability that it fixes, tracked as
CVE-2022-42856, sounds like a nasty one. Websites, for one, can exploit
this flaw to hijack vulnerable phones that surf by.

"Processing maliciously crafted web content may lead to arbitrary code
execution," Apple warned in the security update. "Apple is aware of a this
issue may has been actively exploited against versions of iOS released
before iOS 15.1."

Apple didn't provide any other details about who is responsible for the
in-the-wild exploits. The bug was, however, discovered by Google Threat
Analysis Group's Cl�ment Lecigne, and that's significant because TAG tracks
nation-state attackers and commercial spyware, so it's unlikely that the
CVE-2022-42856 exploits will be attributed to a bunch of script kiddies.

Also, if CVE-2022-42856 sounds familiar, it should. Apple patched the
vulnerability in iOS 16 in December and iOS 15 in November. But not
everyone updates or can update.

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor