po6ix / POC-for-CVE-2023-41993

194 stars 33 forks source link

Tested iPhone 7 GSM (iPhone9,3) iOS 14.8 #16

Open joeyoropesa-dev opened 11 months ago

joeyoropesa-dev commented 11 months ago

Results:

After 2 hours (counted with an stopwatch) of refreshing this PoC website, the exploit is still failed

Probably, the reason is that the vuln doesn't exist (it's not supported) on iOS 14.8 and lower

For iOS 15 and above I didn't test it but since it didn't worked on iOS 14 I'm not sure it will work on any iOS 15.x - after all the vuln is only found in iOS 16 and above and in some versions is patched and in some are not

But this version and lower can be for sure flagged as uneffected versions because the test results are proving unsuccessful exploiting the device with this iOS version that is lower than iOS 15

fullpwn commented 11 months ago

Hey there,

I'm not sure if you're aware of this but iOS 14-15 are not vulnerable to this exploit.

Hope this helps!

joeyoropesa-dev commented 11 months ago

Hey there,

I'm not sure if you're aware of this but iOS 14-15 are not vulnerable to this exploit.

Hope this helps!

Well I don't know why some people said to me that it's vulnerable - after my testing I saw that it's not (at least not for me)

But in this case this also means that iPhone 7 is completely out-of-support of Safari exploit because iPhone 7 doesn't have any iOS 16 version - only iPhone 8 and newer

This should be pinned somewhere (written) to remind people where this bug exist and can be exploited (what devices are supported)