Beautiful Virgin Islands

Wednesday, Nov 05, 2025

Google engineer demonstrate how he could get full control and copy all data from 25 iPhones without touching them

iPhone security? Hmmm... In this demo I remotely trigger an unauthenticated kernel memory corruption vulnerability which causes all iOS devices in radio-proximity to reboot, with no user interaction. Over the next 30'000 words I'll cover the entire process to go from this basic demo to successfully exploiting this vulnerability in order to run arbitrary code on any nearby iOS device and steal all the user data

One of the geniuses working for Google on Project Zero wrote on his blogpost and on his YouTube videos:

Introduction
Quoting @halvarflake's Offensivecon keynote from February 2020:

"Exploits are the closest thing to "magic spells" we experience in the real world: Construct the right incantation, gain remote control over device."

For 6 months of 2020, while locked down in the corner of my bedroom surrounded by my lovely, screaming children, I've been working on a magic spell of my own. No, sadly not an incantation to convince the kids to sleep in until 9am every morning, but instead a wormable radio-proximity exploit which allows me to gain complete control over any iPhone in my vicinity. View all the photos, read all the email, copy all the private messages and monitor everything which happens on there in real-time.

The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine.

Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with.

Imagine the sense of power an attacker with such a capability must feel. As we all pour more and more of our souls into these devices, an attacker can gain a treasure trove of information on an unsuspecting target.

What's more, with directional antennas, higher transmission powers and sensitive receivers the range of such attacks can be considerable.

I have no evidence that these issues were exploited in the wild; I found them myself through manual reverse engineering. But we do know that exploit vendors seemed to take notice of these fixes. For example, take this tweet from Mark Dowd, the co-founder of Azimuth Security, an Australian "market-leading information security business":

Watch the videos and read his full post here.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Massive Spoilers Emerge from MAFS UK 2025: Couple Swaps, Dating App Leaks and Reunion Bombshells
Kurdish-led Crime Network Operates UK Mini-Marts to Exploit Migrants and Sell Illicit Goods
UK Income Tax Hike Could Trigger £1 Billion Cut to Scotland’s Budget, Warns Finance Secretary
Tommy Robinson Acquitted of Terror-related Charge After Phone PIN Dispute
Boris Johnson Condemns Western Support for Hamas at Jewish Community Conference
HII Welcomes UK’s Westley Group to Strengthen AUKUS Submarine Supply Chain
Tragedy in Serbia: Coach Mladen Žižović Collapses During Match and Dies at 44
Diplo Says He Dated Katy Perry — and Justin Trudeau
Dick Cheney, Former U.S. Vice President, Dies at 84
Trump Calls Title Removal of Andrew ‘Tragic Situation’ Amid Royal Fallout
UK Bonds Rally as Chancellor Reeves Briefs Markets Ahead of November Budget
UK Report Backs Generational Smoking Ban Ahead of Tobacco & Vapes Bill Review
UK’s Domino’s Pizza Group Reports Modest Like-for-Like Sales Growth in Q3
UK Supplies Additional Storm Shadow Missiles to Ukraine as Trump Alleges Russian Underground Nuclear Tests
High-Profile Broodmare Puca Sells for Five Million Dollars at Fasig-Tipton ‘Night of the Stars’
Wilt Chamberlain’s One-of-a-Kind ‘Searcher 1’ Supercar Heads to Auction
Erling Haaland’s Remarkable Run: 13 Premier League Goals in 10 Matches and Eyes on History
UK Labour Peer Warns of Emerging ‘Constituency for Hating Jews’ in Britain
UK Home Secretary Admits Loss of Border Control, Warns Public Trust at Risk
President Trump Expresses Sympathy for UK Royal Family After Title Stripping of Prince Andrew
Former Prince Andrew to Lose His Last Military Title as King Charles Moves to End His Public Role
King Charles Relocates Andrew to Sandringham Estate and Strips Titles Amid Epstein Fallout
Two Arrested After Mass Stabbing on UK Train Leaves Ten Hospitalised
Glamour UK Says ‘Stay Mad Jo x’ After Really Big Rowling Backlash
Former Prince Prince Andrew Faces Possible U.S. Congressional Appearance Over Jeffrey Epstein Inquiry
UK Faces £20 Billion Productivity Shortfall as Brexit’s Impact Deepens
UK Chancellor Rachel Reeves Eyes New Council-Tax Bands for High-Value Homes
UK Braces for Major Storm with Snow, Heavy Rain and Winds as High as 769 Miles Wide
U.S. Secures Key Southeast Asia Agreements to Reshape Rare Earth Supply Chains
US and China Agree One-Year Trade Truce After Trump-Xi Talks
BYD Profit Falls 33 % as Chinese EV Maker Doubles Down on Overseas Markets
US Philanthropists Shift Hundreds of Millions to UK to Evade Regulatory Uncertainty in Trump Era
Israeli Energy Minister Delays $35 Billion Gas Export Agreement with Egypt
King Charles Strips Prince Andrew of Titles and Royal Residence
Trump–Putin Budapest Summit Cancelled After Moscow Memo Raises Conditions for Ukraine Talks
Amazon Shares Soar 11% as Cloud Business Hits Fastest Growth Since 2022
Credit Markets Flooded with More Than $200 Billion of AI-Linked Debt Issuance
U.S. Treasury Secretary Scott Bessent Says China Made 'a Real Mistake' by Threatening Rare-Earth Exports
Report Claims Nearly Two Billion Dollars in Foreign Charity Funds Flowed into U.S. Advocacy Groups
White House Refutes Reports That US Targeting Military Sites in Venezuela
Meta Seeks Dismissal of Strike 3’s $350 Million Copyright Lawsuit
Apple Exceeds Forecasts With $102.5 Billion Q3 Revenue Despite iPhone Miss
Israel's IDF Major General Yifat Tomer-Yerushalmi Admits to Act Amounting to Aiding Hamas During Wartime (Treason)
Shawbrook IPO Marks London’s Biggest UK Listing in Two Years
UK Government Split Over Backing Brazil’s $125 Billion Tropical Forest Fund Ahead of COP30
J.K. Rowling Condemns Glamour UK Feature of Nine Trans Women as 'Men Better at Being Women'
King Charles III Removes Prince Andrew’s Titles and Orders His Departure from Royal Lodge
UK Finance Minister Reeves Releases Email Correspondence to Clarify Rental-Licence Breach
UK and Vietnam Sign Landmark Migration Deal to Fast-Track Returns of Irregular Arrivals
UK Drug-Pricing Overhaul Essential for Life-Sciences Ambition, Says GSK Chief
×