Light

Episode #955 Quiz

The Mystery of CVE-2023-38606
Date: 2024-01-02 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Kaspersky traced Operation Triangulation’s zero-click iMessage chain: font RCE, JavaScriptCore privilege escalation, kernel memory read/write, then CVE-2023-38606 disabling Apple’s Page Protection Layer. Apple’s A12-A16 chips exposed undocumented GPU MMIO registers gated by a secret 20-bit hash, allowing signed DMA writes until iOS 16.6 unmapped those ranges.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific mechanism did the attackers use to authenticate writes through the hidden Apple hardware feature before the PPL bypass was applied?
Question 2: What did Apple’s mitigation for CVE-2023-38606 do during boot, according to the episode?
Question 3: Which Apple chip families were said to include the hidden feature discussed in the episode?
Question 4: How did the episode say Kaspersky determined the unknown MMIO blocks were associated with the GPU coprocessor?
Question 5: What was Steve Gibson’s main objection to Kaspersky’s description of the vulnerability as 'security through obscurity'?
Cancel