Google Project Zero reveals six “interactionless” bugs that can affect iOS via Apple’s iMessage

Google Project Zero reveals six “interactionless” bugs that can affect iOS via Apple’s iMessage


Yesterday, two members of the Google Project Zero team revealed about six “interactionless” security bugs that can affect iOS by exploiting the iMessage Client. Four of these bugs can execute malicious code on a remote iOS device, without any prior user interaction.


Apple released fixes for these bugs in the iOS 12.4 update on July 22. The two Project Zero researchers, Natalie Silvanovich and Samuel Groß, published details and demo proof-of-concept only for five out of the six vulnerabilities. Details of one of the “interactionless” vulnerabilities have been kept private because Apple’s iOS 12.4 patch did not completely resolve the bug, according to Natalie Silvanovich.



We are withholding CVE-2019-8641 until its deadline because the fix in the advisory did not resolve the vulnerability


— Natalie Silvanovich (@natashenka) July 29, 2019



4 bugs can perform an RCE via a malformed message


Bugs with vulnerability IDs, CVE-2019-8647, CVE-2019-8660, google project reveals interactionless affect apple imessage