logo

The curious tale of a fake Carrier.app

ID: 3f2805ee-31c5-56fd-a969-03803d905ce5

STIX ID: report--3f2805ee-31c5-56fd-a969-03803d905ce5

Feed Name: Google Project Zero

Threat Score
90/100

Date Published: 2022-06-23

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

Google Project Zero analysed a real-world iOS privilege-escalation exploit (CVE-2021-30983) delivered via a sideloaded fake “My Vodafone” carrier app; the exploit abused the Display Co-Processor (DCP) RPC and memory-mapping interfaces to obtain kernel read/write primitives and enable data exfiltration. The post details DCP firmware reverse-engineering, the exploit flow from IOConnectCallMethod through DCP handlers to a UniformityCompensator overflow, and notes the vulnerability was patched in iOS 15.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.