iOS

Alfie CG publishes write-up on Trigon, a deterministic kernel exploit based on CVE-2023-32434 that can’t fail

Matrix code hacked iPhone.

Another week, another intriguing write-up by the young and talented hobbyist security researcher @alfiecg_dev, who just this weekend published a blog post about a new deterministic kernel exploit called Trigon that is based on CVE-2023-32434, the same bug that the Kernel File Descriptor (KFD) exploit utilized with puaf_smith and was patched in iOS & iPadOS 16.5.1.

Security researcher wh1te4ever shares Safari-based remote execution exploit patched in iOS 16.5.1, macOS 13.4.1

MacBook Pro Matrix Hack banner image.

In case you weren’t already aware, there was a Safari-based remote code execution (RCE) bug in the wild that Apple patched in a rapid security update for iOS & iPadOS 16.5.1 dubbed CVE-2023-37450, and ENKI WhiteHat is credited with the original proof of concept (PoC) showcasing the bug. But what if we told you someone made an exploit out of it? Interestingly enough, that seems to be exactly what has happened.

Prevent over-shoulder passcode snooping attacks with the Rode jailbreak tweak

Rode banner.

One of my biggest qualms with the Lock Screen on any iPhone or iPad is the fact that the number pad for passcode entry always has the same layout. This means that even if someone who’s glancing over your shoulder doesn’t know exactly what numbers you’re tapping on, they can instead easily memorize the positions of the number buttons you tap on to gain access to your device.

How to change the root user password on a rootless jailbreak with NewTerm

How to change root user password banner image.

We previously showed you how you can change the root user password on your jailbroken handset with an on-device terminal app like NewTerm. But since then, the process has changed slightly, especially if using modern rootless jailbreaks on iOS or iPadOS 15 and later, such as Dopamine or palera1n. Fortunately, we will share the updated process with you in today’s tutorial.