Plug'nPwn – Connect to Jailbreak(blog.t8012.dev)
blog.t8012.dev
Plug'nPwn – Connect to Jailbreak
https://blog.t8012.dev/plug-n-pwn/
3 comments
Apple T2 vulnerability was reported before, but this goes into detail on a potential attack scenario.
The full timeline + previous coverage is here:
https://blog.t8012.dev/on-bridgeos-t2-research/
The lack of response to this from Apple is deeply disappointing. The attack isn't technically persistent - rebooting the T2 will clear it. But the T2 doesn't reboot when the host OS does, and Apple haven't published any guidance on how to guarantee that it has been (eg, does holding the power button down for long enough cut power to the T2? Does performing an SMC reset? Both seem to, but is that guaranteed to be the case if the T2 is running malicious code?). In addition, the Blackbird SEP exploit probably means that we have to assume that all secrets kept in the Secure Enclave can be stolen - but we don't have a full enumeration of what those typically are, or what the security impact of this is as a result.