vendor:
iPhone OS
by:
Ian Beer
8,8
CVSS
HIGH
Code Execution
N/A
CWE
Product Name: iPhone OS
Affected Version From: iOS 10.2
Affected Version To: iOS 10.3.3
Patch Exists: YES
Related CWE: N/A
CPE: o:apple:iphone_os:10.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2017
FoV-1289: Wi-Fi Firmware Backdoor on iPhone 7
This exploit gains code execution on the Wi-Fi firmware on the iPhone 7. It has been tested against the Wi-Fi firmware as present on iOS 10.2 (14C92), but should work on all versions of iOS up to 10.3.3 (included). Upon successful execution of the exploit, a backdoor is inserted into the firmware, allowing remote read/write commands to be issued to the firmware via crafted action frames.
Mitigation:
Apple has released a patch for this vulnerability.