logo

Blasting Past Webp

ID: f433e056-0506-528b-8d28-decdd0f2f698

STIX ID: report--f433e056-0506-528b-8d28-decdd0f2f698

Feed Name: Google Project Zero

Threat Score
95/100

Date Published: 2025-03-26

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

This blog-post–style technical writeup by Google Project Zero analyzes BLASTPASS, an NSO Group zero-click iMessage exploit that used a lossless WebP memory corruption (exploited in the wild) combined with a large MakerNote binary-plist heap groom inside a PKPass to achieve code execution and BlastDoor sandbox escape on iOS; the chain included allocator metadata corruption, crafted TIFF/WebP payloads, ASLR disclosure (likely via HomeKit), and a callback-oriented JOP technique to bypass ARM Pointer Authentication and bootstrap an encrypted NSExpression payload for final payload delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.