The curious tale of a fake Carrier.app
ID: 3f2805ee-31c5-56fd-a969-03803d905ce5
STIX ID: report--3f2805ee-31c5-56fd-a969-03803d905ce5
Feed Name: Google Project Zero
Google Project Zero analysed a real-world iOS privilege-escalation exploit (CVE-2021-30983) delivered via a sideloaded fake “My Vodafone” carrier app; the exploit abused the Display Co-Processor (DCP) RPC and memory-mapping interfaces to obtain kernel read/write primitives and enable data exfiltration. The post details DCP firmware reverse-engineering, the exploit flow from IOConnectCallMethod through DCP handlers to a UniformityCompensator overflow, and notes the vulnerability was patched in iOS 15.2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
