iOS 15.2 fixed many bugs in IOMobileFrameBuffer (IOMBF), one of my favorite attack surfaces, and brought me a lot of good memories regarding IOMBF.
I got to notice IOMBF because of JailbreakMe (Star) by comex et al. It was widely believed that the integer overflow in IOSurface (CVE-2010-2973) was the kernel vulnerability exploited by Star, as described by the advisory. In fact, there was a stack-based OOB write in IOMBF.
Dec 7, 2021 • 5 tweets • 1 min read
I have been working on iOS security research since iOS 5. Now iOS 15 has come out. I don’t remember how many times, after I completed a jailbreak exploit, I told myself this was the last one. However, when a new version of iOS is released, I can't help myself to start again.
Deep down in my heart, I know I’m afraid that one day I would be unable to create jailbreak exploits anymore. Luckily enough, I'm still keeping the capability now. However, iOS has unknowingly become my conformable zone.