vendor:
iPhone 7
by:
Project Zero
8,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: iPhone 7
Affected Version From: iOS 10.2 (14C92)
Affected Version To: iOS 10.2 (14C92)
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2020
Exploit for R/W Access to Host’s Physical Memory
This exploit has been tested on the iPhone 7, iOS 10.2 (14C92). To run the exploit against different devices or versions, the symbols must be adjusted. The exploit requires the user to connect a SoftMAC Wi-Fi dongle to their machine, compile a modified version of hostapd, modify the hostapd.conf file, configure the settings in the conf.py files, assemble the backdoor shellcode, assemble the code chunks, run hostapd, connect the target device to the network, and then run the attack.py file.
Mitigation:
N/A