iPhone無法修復的永久漏洞被發現 可無限JB - iOS

Caitlin avatar
By Caitlin
at 2019-09-28T01:48

Table of Contents

※ [本文轉錄自 MobileComm 看板 #1TZajpCu ]

作者: kyle5241 (Kyle Korver) 看板: MobileComm
標題: [新聞]iPhone無法修復的永久漏洞被發現 可無限JB
時間: Sat Sep 28 01:48:31 2019

https://tinyurl.com/y3p8zeej

New ‘unpatchable’ iPhone exploit could allow permanent jailbreaking on
hundreds of millions of devices

新的無法修復的iPhone漏洞讓iPhone可以永久越獄


A newly announced iOS exploit could lead to a permanent, unblockable
jailbreak on hundreds of millions of iPhones, according to researcher axi0mX
who discovered it. Dubbed “checkm8,” the exploit is a bootrom vulnerability
that could give hackers deep access to iOS devices on a level that Apple
would be unable to block or patch out with a future software update. That
would make it one of the biggest developments in the iPhone hacking community
in years.

新公佈的iOS漏洞將導致上億隻iPhone永久、無法阻擋的越獄。這個漏洞利用了開機檔
的弱點讓人們可以取得深層iOS的權限,但蘋果卻沒有任何辦法可以修補它。


EPIC JAILBREAK: Introducing checkm8 (read "checkmate"), a permanent
unpatchable bootrom exploit for hundreds of millions of iOS devices.

Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5
chip) to iPhone 8 and iPhone X (A11 chip). https://github.com/axi0mX/ipwndfu

所有A11晶片以下的機種都將可以永久JB


The exploit is specifically a bootrom exploit, meaning it’s taking advantage
of a security vulnerability in the initial code that iOS devices load when
they boot up. And since it’s ROM (read-only memory), it can’t be
overwritten or patched by Apple through a software update, so it’s here to
stay. It’s the first bootrom-level exploit publicly released for an iOS
device since the iPhone 4, which was released almost a decade ago.

這個漏洞是開機碼漏洞,利用iOS開機時的啟動碼的弱點。這個起動碼只能讀,不能寫。
所以蘋果沒有辦法藉由軟體更新去更動它。自從iPhone 4以來,這是第一個開機碼層面
的漏洞,上次找到已經是10年前的事。

In a follow-up tweet, axi0mX explained that they released the exploit to the
public because a “bootrom exploit for older devices makes iOS better for
everyone. Jailbreakers and tweak developers will be able to jailbreak their
phones on latest version, and they will not need to stay on older iOS
versions waiting for a jailbreak. They will be safer.”

axi0mX解釋說公布這個漏洞是希望讓iOS的舊裝置更好。JB開發者總是可以在最新的
iOS版本越獄,他們不需要卡在比較不安全的舊版本,所以他們越獄的手機會更安全

Hundreds of millions of iPhone devices are affected by the exploit: any
device starting with an iPhone 4S (A5 chip) through the iPhone 8 and iPhone X
(A11 chip) is vulnerable, although it appears that Apple patched the flaw in
last year’s A12 processors, meaning that iPhone XS / XR and 11 / 11 Pro
devices won’t be affected.

上億隻iPhone受到這個漏洞的影響,A11以下的機種都可以越獄。
但蘋果在A12以後的機種修復了這個漏洞



心得:

蘋果啊~與其叫我們改買iphone 11,我是覺得啦~

你推出一個花$100 舊機種換iPhone XR的活動好了~

這樣表示出一個企業的良心

順便把所有沒有face ID的機種消滅

把所有3D touch的機種消滅。

剛好一舉兩得

--
Tags: iOS

All Comments

Ina avatar
By Ina
at 2019-09-30T12:34
什麼心得
Gary avatar
By Gary
at 2019-10-05T01:41
翻譯有翻錯,上一次同一位開發者找出3GS的alloc8漏洞
根本才兩年前的事。
Bennie avatar
By Bennie
at 2019-10-09T17:02
好爛的心得
Rosalind avatar
By Rosalind
at 2019-10-13T03:08
心得在打三小
Skylar Davis avatar
By Skylar Davis
at 2019-10-17T17:11
心得
Bennie avatar
By Bennie
at 2019-10-21T14:26
看了一下推特 可以期待
Margaret avatar
By Margaret
at 2019-10-23T08:53
都2019了還有人覺得越獄刷機要低調XD
Annie avatar
By Annie
at 2019-10-24T18:48
我的i5又能再戰惹嗎!?
Oscar avatar
By Oscar
at 2019-10-25T18:58
r以後只能買原廠線了,不然線一插就被破解在裝一堆殭屍
Liam avatar
By Liam
at 2019-10-25T21:58
這邏輯 那安卓連安全性更新都更不齊不就賠死
Dora avatar
By Dora
at 2019-10-30T01:50
那為何我的ipad air2無法JB?

iOS 13.1.1 更新

Zanna avatar
By Zanna
at 2019-09-28T01:18
修正了 iPhone 無法從備份回復的問題 解決了可能導致電池電量消耗過快的問題 修正了可能在 iPhone 11、iPhone 11 Pro 和 iPhone 11 Pro Max 上影響辨識 Siri 要求 的問題 解決了關閉 Safari 搜尋建議後可能又重新啟用的問題 解決了可能導致「提醒事項」同步緩 ...

iOS 13.1.1 出爐

Xanthe avatar
By Xanthe
at 2019-09-28T01:14
已知修正項目: - Fixes issues that could prevent iPhone restoring from backup 修復iPhone可能無法從備份還原的問題 - Addresses an issue that could cause battery to drain more ...

XS Max 更新ios13.1

Belly avatar
By Belly
at 2019-09-28T01:05
請問各位大大!我的XS Max更新到ios13.1後,發現手機來電(Line也是)沒有鈴聲也沒 有振動. 本來是用OTA升級的,今天再用電腦回復ㄧ次. 結果還是ㄧ樣!確定沒有關到靜 音. 不知有沒有人也有一樣的情況?很傷腦筋. - ...

IOS久違的漏洞

Poppy avatar
By Poppy
at 2019-09-28T00:17
如題,今天一打開推特,整個版面都被越獄圈洗版,原來是有開發者(ataxi0mX), 釋出了From A5(iphone4S) to A11(iphone8/X) 的 checkm8 漏洞, https://imgur.com/a/KOVyMIc 此漏洞源於作者找到蘋果在去年的iOS 12 Beta中修補的i ...

請問ios13.1 xs要如何在主畫面解除app

Carol avatar
By Carol
at 2019-09-28T00:16
請問ios13.1 iphone xs要如何在主畫面解除app 之前12.多時候輕觸app右上角就會出現一個x的符號可以按然後解除安裝 更新後不管輕按重按都只有分享跑出來 有大大能幫測試嗎 - ...