NEWS

Google Confirms Apple iPhone Bricking iMessage Bomb

07/08/2019

2654

Google Confirms Apple iPhone Bricking iMessage Bomb


Google's Project Zero exists to hunt down zero-day vulnerabilities such as the yet to be fixed Windows 10 security bomb I wrote about recently. But it's not just Microsoft that comes under scrutiny from the Google security researchers: a vulnerability in Apple's iMessage has been found that "bricks" an iPhone and survives hard resets, leaving users having to wipe the device and start factory fresh again.


The iMessage text bombing zero-day was disclosed by Google Project Zero researcher Natalie Silvanovich, who describes how the malformed message vulnerability can cause a Mac to "crash and respawn." However, as Silvanovich notes in her disclosure, "on an iPhone, this code is in Springboard. Receiving this message will cause Springboard to crash and respawn repeatedly, causing the UI not to be displayed and the phone to stop responding to input." In other words, receiving this text bomb through iMessage creates a condition that survives a hard reset and causes the iPhone to be unusable from the moment it is unlocked. "The only way I could find to fix the phone is to reboot into recovery mode and do a restore," Silvanovich said, continuing "this causes the data on the device to be lost though."


As long as you keep your iPhone up to date, however, there is no need to panic. The Google Project Zero disclosure policy is to allow the vendor, Apple, in this case, 90 days from the point of informing it of the vulnerability to issue a fix. After that 90 days has elapsed, or a fix has been made available, the vulnerability report will be disclosed to the public. That's what has happened this week, with Silvanovich hitting the publish button on her April 19 bug report. Apple actually fixed the problem really quickly as part of the iOS 12.3 release on May 13. Even so, Silvanovich left plenty of extra time to ensure the fix has been made as broadly available as possible before disclosing the existence of the problem this week.


If you haven't turned on the automatic software update feature in iOS 12, then I recommend that you do. That way you can be sure that issues like the iMessage text bomb iPhone bricker will not impact you. Simply open the Settings app, navigate to the General section, and then select the software update option. Toggle the automatic updates button to on and you are sorted. It goes without saying, but I will say it anyway: if you are not yet running iOS 12.3, then you really should update as a matter of urgency now that the iMessage bricking technique has been made public. Sure, there are always going to be some concerns about updating to a new version of any operating system, and the forthcoming iOS 13 is not immune to these, but updating makes more sense than not if you want to reduce the risk of falling victim to known security issues that could make your iPhone unusable.


source: forbes

Windows
Mac OS
iOS
Linux
3uTools
Win 64-bit For this device
V9.01 2025-12-27
Download
Win 32-bit For this device
V9.01 2025-12-27
Download
3uTools
Intel Chip How to Identify Chip Type
V9.01 2025-12-31
Download
Apple Silicon
V9.01 2025-12-31
Download
How to Identify Chip Type
1.  Click the Apple icon in the top-left corner of the screen and select About This Mac.
2.  Check the Processor or Chip field to determine if it is "Intel" or "Apple".
Please use the 3uTools PC client to install the iOS client:
1、 Install either the Windows or Mac version of 3uTools on your computer
2、 Open the PC client and connect your device to the computer via USB cable
3、 After the connection is successful, wait for the computer to automatically install the mobile app for the device, or locate “Install Mobile App” on the computer and manually click to install.
3uTools
deb file
V3.01 2025-11-20
Download
rpm file
V3.01 2025-11-20
Download
Windows
Windows
iOS
iOS
Android
Android
TV
TV
3uAirPlayer
Win 64-bit For this device
V6.0.2 2025-11-19
Download
Win 32-bit For this device
V6.0.2 2025-11-19
Download
iOS Device Mirroring (No App Required)
1、 Install 3uAirPlayer on the Windows PC
2、 Open Control Center and select Screen Mirroring
3、 From the list, choose your PC to start mirroring
4、 Or connect your iOS device to the PC via USB to begin mirroring
Scan to get "3uAirPlayer" App
3uAirPlayer TV V1.0.18
2025-11-28
TV System Requirements: Android 7.0 or later
Download the TV installation package, copy it to a USB drive, insert it into your TV or set-top box, then select the file from the home screen to install.