Warning: ini_set(): Session ini settings cannot be changed when a session is active in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 12

Warning: Trying to access array offset on value of type null in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1071

Warning: Trying to access array offset on value of type null in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1072

Warning: Undefined array key 1 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 2 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 3 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 4 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 5 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined variable $link_subfolder1 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1134

Warning: Undefined variable $meta_article in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 100

Warning: Undefined variable $meta_og in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 100

Warning: Undefined variable $meta_twitter in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 100

Warning: Undefined variable $login_loggedon_html in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 142
iPhone 0-click spyware campaign 'Triangulation' detailed | CyberSecurityBoard

Warning: Undefined variable $comments_html in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 527

iPhone 0-click spyware campaign 'Triangulation' detailed

Months after blowing the whistle on a sophisticated campaign that dropped full-featured spyware onto iPhones, researchers have disclosed more about the attack's complex exploit chain that abused four separate vulnerabilities.
Among the finding are that the zero-click attacks took advantage of a flaw in an undocumented Apple hardware security feature.
This enabled attackers to manipulate the contents of secure memory, and ultimately gain full control of iPhones, and potentially other Apple devices.
Kaspersky presented its findings at the 37th Chaos Communications Congress in Hamburg, Germany, on Dec. 27 and, on the same day, its Global Research and Analysis Team published a research post outlining its discoveries.
The vulnerability, tracked as CVE-2023-38606, has since been patched by Apple, as have the three other bugs in the Operation Triangulation exploit chain: CVE-2023-41990, CVE-2023-32434, and CVE-2023-32435.
The Operation Triangulation attacks began with the threat actors sending a malicious iMessage containing an attachment to the target iPhone which was processed without the user being aware of it.
The iMessage attachment exploited CVE-2023-41990, a remote code execution vulnerability in the Apple-only ADJUST TrueType font instruction.
Once the exploit chain was complete, and the spyware was installed, the attackers had complete control of their target's device, allowing them to carry out a range of espionage activities including transmitting the phone's contents to their servers.
Although the spyware was wiped when the phone was rebooted, that did not stop the attackers reloading the malware and taking control of the device again.
Kaspersky discovered the malware was designed to work on MacOS devices, IPads, Apple TVs and Apple Watches as well as iPhones.
CoreSight is the debug-and-trace architecture used by chipmaker ARM, an apple supplier.


This Cyber News was published on packetstormsecurity.com. Publication date: Thu, 28 Dec 2023 16:13:05 +0000


Cyber News related to iPhone 0-click spyware campaign 'Triangulation' detailed


Fatal error: Uncaught mysqli_sql_exception: You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near 'Triangulation' detailed') AS score FROM TPL_articles WHERE urlarray1_seo!='pa...' at line 1 in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php:336 Stack trace: #0 /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php(336): mysqli_query() #1 /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php(548): template_block() #2 /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php(531): template_related() #3 /home/u319666691/domains/cybersecurityboard.com/public_html/index.php(1135): template_content() #4 {main} thrown in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 336