New Crucial Vulnerabilities in Apple's bluetoothd daemon
ID: 62c7dd7e-26e5-5077-9a77-c20205f11e2d
STIX ID: report--62c7dd7e-26e5-5077-9a77-c20205f11e2d
Feed Name: Zimperium Blog
Threat Score
Zimperium zLabs discovered two critical CoreBluetooth vulnerabilities in the bluetoothd daemon (CVE-2018-4087 and CVE-2018-4095) that allow stack-based memory corruption and arbitrary code execution across many system daemons on iOS, tvOS and watchOS, effectively enabling sandbox escapes and privilege escalation; Apple released patches in iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 and a detailed technical write-up and exploit code are promised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
