An iMessage EXR attachment reaches privileged background processing without a tap and causes attacker-controlled heap corruption.
Affects
Apple iOS and iPadOS devices whose background photo-processing services automatically decode EXR attachments received through iMessage.
The decoder allocates 12 bytes per RGB pixel and writes 16 attacker-controlled bytes, after Messages and the photo subsystem route the unopened attachment into libAppleEXR.
Detail and 3 sources
The researcher reached arbitrary write and program-counter control in a harness, but did not demonstrate clean cross-process code execution because the remaining path requires a PAC-signed pointer.
Apple has fixed the ImageIO flaw.
Chain to watch
Gain an information leak or PAC bypass in the privileged background process→↓Convert the controlled overwrite into clean cross-process execution→↓Test the path on hardware with and without Memory Integrity Enforcement→↓Clean code execution in the real privileged process remains unproven, and hardware protections change the result.
Unverified chainDemonstrate an information leak or PAC bypass in the real process and test across protected and unprotected hardware generations.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.