CVE-2018-4087 PoC: Escaping the sandbox by misleading bluetoothd
ID: bba3f2d7-f37d-5149-95b9-a3cd7e3cd73c
STIX ID: report--bba3f2d7-f37d-5149-95b9-a3cd7e3cd73c
Feed Name: Zimperium Blog
Threat Score
This blog post discloses two vulnerabilities in Apple's bluetoothd IPC that allowed a sandboxed app to brute-force session tokens (mach_port_t) and register callbacks on other system clients—enabling mach port leakage and potential sandbox escape; the author provides PoC code, lists affected clients, assigned CVEs (CVE-2018-4087, CVE-2018-4095), and notes Apple patched the issue by randomizing session tokens in iOS/watchOS/tvOS updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
