{"id":40594,"date":"2023-09-08T13:31:44","date_gmt":"2023-09-08T17:31:44","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=40594"},"modified":"2024-09-16T20:44:51","modified_gmt":"2024-09-17T00:44:51","slug":"blastpass","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2023\/09\/08\/blastpass\/","title":{"rendered":"BLASTPASS"},"content":{"rendered":"<p><a href=\"https:\/\/www.macrumors.com\/2023\/09\/07\/ios-16-6-1-macos-13-5-2-active-vulnerabilities\/\">Juli Clover<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=37425007\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2023\/09\/07\/ios-16-6-1-macos-13-5-2-active-vulnerabilities\/\">\n<p>[A] maliciously crafted image could lead to arbitrary code execution, allowing a hacker to gain access to the operating system with a simple picture.<\/p>\n<p>[&#8230;]<\/p>\n<p>As <a href=\"https:\/\/citizenlab.ca\/2023\/09\/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild\/\">reported by Citizen Lab<\/a>, the vulnerabilities are part of a &ldquo;BLASTPASS&rdquo; exploit chain that was observed having been used in the wild to deliver NSO Group&rsquo;s Pegasus spyware. Pegasus is of critical concern to government officials, journalists, activists, and others with potentially sensitive information on their devices.<\/p><p>The zero-click vulnerability allowed attackers to send a maliciously crafted PassKit (Wallet) image to a target via iMessage, infecting their device &ldquo;without any interaction from the victim.&rdquo;<\/p><\/blockquote>\n<p>Lockdown Mode blocks this particular attack. It&rsquo;s not really clear to me why these images can&rsquo;t be safely processed behind the Blast Door. Is it because they&rsquo;re related to other cross-cutting iOS services such as PassKit? That is, if iMessage were <em>just<\/em> a messaging service, it would be easier to make it secure. If Messages were restricted to doing what third-party apps can do, maybe these sorts of vulnerabilities would be impossible. But it&rsquo;s also become the transport for various other iOS features and Apple services, so it&rsquo;s necessarily hooked deeper into the system. If I lived in Europe, maybe I could just disable iMessage and use WhatsApp, which is arguably more reliable and secure.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/09\/08\/macos-13-5-2\/\">macOS 13.5.2<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/09\/08\/ios-16-6-1-and-ipados-16-6-1\/\">iOS 16.6.1 and iPadOS 16.6.1<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/09\/06\/dma-gatekeepers-designated\/\">DMA Gatekeepers Designated<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/06\/27\/triangulation-exploit\/\">Triangulation Exploit<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/04\/27\/zero-click-exploits-against-ios-16\/\">Zero-Click Exploits Against iOS 16<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/10\/17\/whatsapp-more-private-than-imessage\/\">WhatsApp More Private Than iMessage<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/08\/10\/time-for-apple-to-fix-texting\/\">Time for Apple to Fix Texting<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/07\/06\/lockdown-mode\/\">Lockdown Mode<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/11\/24\/apple-sues-nso-group\/\">Apple Sues NSO Group<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/13\/zero-click-imessage-attacks\/\">Zero-click iMessage Attacks<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/07\/23\/through-the-blast-door\/\">Through the Blast Door<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/02\/01\/imessages-blastdoor-sandbox\/\">iMessage&rsquo;s BlastDoor Sandbox<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Juli Clover (Hacker News): [A] maliciously crafted image could lead to arbitrary code execution, allowing a hacker to gain access to the operating system with a simple picture. [&#8230;] As reported by Citizen Lab, the vulnerabilities are part of a &ldquo;BLASTPASS&rdquo; exploit chain that was observed having been used in the wild to deliver NSO [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2023-09-08T17:31:46Z","apple_news_api_id":"1f25279f-d8ca-4149-a21a-e4ac9af1f59f","apple_news_api_modified_at":"2023-09-09T10:44:23Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AHyUnn9jKQUmiGuSsmvH1nw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[131,140,31,2185,2242,2657,48,1363],"class_list":["post-40594","post","type-post","status-publish","format-standard","hentry","category-technology","tag-bug","tag-imessage","tag-ios","tag-ios-16","tag-lockdown-mode","tag-nso-group","tag-security","tag-whatsapp"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/40594","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=40594"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/40594\/revisions"}],"predecessor-version":[{"id":40601,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/40594\/revisions\/40601"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=40594"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=40594"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=40594"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}