London Daily

Focus on the big picture.
Tuesday, Jun 16, 2026

Google engineer demonstrate how he could get full control and copy all data from 25 iPhones without touching them

iPhone security? Hmmm... In this demo I remotely trigger an unauthenticated kernel memory corruption vulnerability which causes all iOS devices in radio-proximity to reboot, with no user interaction. Over the next 30'000 words I'll cover the entire process to go from this basic demo to successfully exploiting this vulnerability in order to run arbitrary code on any nearby iOS device and steal all the user data

One of the geniuses working for Google on Project Zero wrote on his blogpost and on his YouTube videos:

Introduction
Quoting @halvarflake's Offensivecon keynote from February 2020:

"Exploits are the closest thing to "magic spells" we experience in the real world: Construct the right incantation, gain remote control over device."

For 6 months of 2020, while locked down in the corner of my bedroom surrounded by my lovely, screaming children, I've been working on a magic spell of my own. No, sadly not an incantation to convince the kids to sleep in until 9am every morning, but instead a wormable radio-proximity exploit which allows me to gain complete control over any iPhone in my vicinity. View all the photos, read all the email, copy all the private messages and monitor everything which happens on there in real-time.

The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine.

Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with.

Imagine the sense of power an attacker with such a capability must feel. As we all pour more and more of our souls into these devices, an attacker can gain a treasure trove of information on an unsuspecting target.

What's more, with directional antennas, higher transmission powers and sensitive receivers the range of such attacks can be considerable.

I have no evidence that these issues were exploited in the wild; I found them myself through manual reverse engineering. But we do know that exploit vendors seemed to take notice of these fixes. For example, take this tweet from Mark Dowd, the co-founder of Azimuth Security, an Australian "market-leading information security business":

Watch the videos and read his full post here.

Newsletter

Related Articles

0:00
0:00
Close
Government Advances New Airport Slot Rules to Ease Airline Operating Constraints
BBC Opens Flagship Science-Fiction Franchise to Competitive Production Bids
Chancellor Meets City Leaders Amid Concerns Over Gilt Market Liquidity
Rathbones Shares Fall Seventeen Percent After Regulatory Review Reveals Compliance Failings
United Kingdom Joins Group of Seven Initiative Using Artificial Intelligence and Quantum Computing for Cancer Research
Parliament Debates Doubling Tax Allowance for Pensioners After Major Public Petition
Measles Cases Exceed Seven Hundred in London and the West Midlands
British Military Leadership Faces Parliamentary Scrutiny After Defence Secretary's Sudden Resignation
House of Lords Begins Debate on Steel Industry Nationalisation Legislation
Parliament Advances Bill to Abolish NHS England and Create Single Patient Records
Parliament Fast-Tracks National Security Bill to Expand Powers Against Foreign Threats
United Kingdom and European Union Set July Summit to Deepen Post-Brexit Cooperation
United Kingdom Imposes Seventy New Sanctions on Russia and Expands Support for Ukraine's Nuclear Sector
United Kingdom Announces Social Media Ban for Children Under Sixteen
0British Government Investigates Reports of Russian Warship Firing Warning Shots Near Isle of Wight
UK Supreme Court Revises Legal Definition of Deprivation of Liberty
King’s Birthday Honours Recognise Contributions Across Science, Culture and Public Service
UK Ministry of Defence Reports Interdiction of Russian Shadow Fleet Vessel
UK and US Launch Joint Regulatory Programme for Medicines and Healthcare Products
Solicitor General Refers Murder Sentence to Court of Appeal Under Unduly Lenient Scheme
UK Launches £1.6 Million Mobile Museum Initiative to Expand Cultural Access
Judicial Pay Structure Undergoes Government Review Following Senior Recommendations
Government Confirms Nearly 180 New Youth Hubs Across the United Kingdom
UK Government Expands Careers Support Through Partnership with LinkedIn
Digital News Report Highlights Growing Global Concern Over AI and Information Overload
UK Chancellor Reaffirms Fiscal Discipline and Borrowing Reduction Strategy
UK Government Invests £219 Million in Sustainable Aviation Fuel Development
Rolls-Royce Small Modular Reactors Secures Major Swedish Export Contract
Government Confirms Locations for Nearly 180 Youth Hubs Across Great Britain
UK Government Partners with LinkedIn to Expand Employment Support Services
Reuters Institute Report Flags Rising Public Anxiety Over News and Information Overload
UK Government Commits £219 Million to Expand Sustainable Aviation Fuel Industry
Chancellor Convenes Market Engagement Group to Assess UK Economic Outlook and Productivity Risks
Rolls-Royce Wins Multibillion-Pound Swedish Contract for Small Modular Nuclear Reactors
Government to Ban Social Media Access for Under-Sixteens Across the United Kingdom
Government Approves Fast-Tracked Broadcast Merger Reshaping UK's Media Landscape
Resignation of Defence Secretary John Healey Triggers Debate Over UK Military Strategy
Britain Intensifies Diplomatic Efforts to Support US-Iran Ceasefire
Bank of England Faces Tough Interest Rate Choices After Economic Contraction
Belfast Sees Second Day of Anti-Migrant Riots as Police Deploy Water Cannons
UK Economy Shrinks in April as Energy Price Shocks Weigh on Growth
UK to Ban Social Media Access for Children Under 16 From 2027
UK Parliament Opens Week of Fast-Tracked Security and Infrastructure Legislation
Northern Ireland Projects £21 Million Boost From Major Cultural and Sporting Events
UK and Japan Sign Technology Security Pact to Strengthen AI and Supply Chain Cooperation
UK Welcomes US-Iran Peace Breakthrough Aimed at Restoring Strait of Hormuz Shipping
British Forces Intercept Russian Shadow Fleet Oil Tanker in English Channel Sanctions Operation
UK to Ban Social Media for Under-16s Under Landmark Online Safety Expansion
Anti-Immigrant Riots Spread Across Belfast, Raising Security Concerns
Ministry of Defence Opens Europe's Largest Drone Testing Facility in Swindon
×