36C3 - Messenger Hacking: Remotely Compromising an iPhone through iMessage
https://media.ccc.de/v/36c3-10497-mes... So called “0-click” exploits, in which no user interaction is required to compromise a mobile device, have become a highly interesting topic for security researchers, and not just because Apple announced a one million dollar bug bounty for such exploits against the iPhone this year. This talk will go into the details of how a single memory corruption vulnerability in iMessage was remotely exploited to compromise an iPhone. The insights gained from the exploitation process will hopefully help defend against such attacks in the future. This talk will dive into the internals of an iMessage exploit that achieves unsandboxed remote code execution on vulnerable devices (all iPhones and potentially other iDevices up to iOS 12.4) without user interaction and within a couple of minutes. All that is necessary for a successful attack in a default configuration is knowledge of the target’s phone number or an email address. Further, the attack is also possible without any visible indicators of the attack displayed to the user. First, an overview of the general iMessage software architecture will be given, followed by an introduction of the exploited vulnerability. Next, a walkthrough of the exploitation process, including details about how the various exploit mitigations deployed on iOS were bypassed, will be presented. Some of the exploitation techniques are rather generic and should be applicable to exploit other vulnerabilities, messengers, and even other platforms such as Android. Along the way, some advice will be shared with the audience on how to bootstrap research in this area. The talk concludes with a set of suggestions for mobile OS and messenger vendors on how to mitigate the demonstrated exploit techniques effectively and hopefully make these kinds of attacks significantly more difficult/costly to perform in the future. While previous experience with iOS userland exploitation will not be required for this talk, some basic background knowledge on memory corruption vulnerabilities is recommended. Samuel Groß https://fahrplan.events.ccc.de/congre...

36C3 - How to Break PDFs

36C3 - The Great Escape of ESXi

Attacking AI - Jason Haddix - NDC Security 2026

The Day China Hacked Google: Operation Aurora

36C3 - SIM card technology from A-Z

36C3 - The One Weird Trick SecureROM Hates

Trump Attends NBA Finals, Cries Election Fraud in California & Storms Out of Interview

36C3 - #mifail oder: Mit Gigaset wäre das nicht passiert!
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

36C3 - Open Source is Insufficient to Solve Trust Problems in Hardware

36C3 - Uncover, Understand, Own - Regaining Control Over Your AMD CPU

SwiftUI Course for Beginners – Create an iOS App from Scratch

Exploiting Common iOS Apps’ Vulnerabilities

Hacking cell phones like Mr Robot

BlueHat IL 2019 - Luca Todesco (@qwertyoruiop) - Life as an iOS Attacker

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

iOS Kernel PAC, One Year Later

"Hack ANY Cell Phone" - Hacker Shows How Easy It Is To Hack Your Cell Phone

How to Disappear Online and Become Untraceable

