Security

Technical analysis by Verichains confirms sandbox escape use by certain banking apps to detect TrollStore, jailbreak apps

iPhone hacked matrix.

Just yesterday, we reported on one of TrollStore perma-signing utility developer Lars Fröder’s posts on Bluesky sharing that some banking apps available in Apple’s App Store as of this writing utilize a 0-day sandbox escape technique to find out if certain unfavorable apps or services are installed on the end user’s device.

Alfie CG publishes write-up on Trigon, a deterministic kernel exploit based on CVE-2023-32434 that can’t fail

Matrix code hacked iPhone.

Another week, another intriguing write-up by the young and talented hobbyist security researcher @alfiecg_dev, who just this weekend published a blog post about a new deterministic kernel exploit called Trigon that is based on CVE-2023-32434, the same bug that the Kernel File Descriptor (KFD) exploit utilized with puaf_smith and was patched in iOS & iPadOS 16.5.1.