zlacker

[return to "'Text bomb' is latest Apple bug"]
1. devit+G8[view] [source] 2018-01-18 16:00:43
>>Harvey+(OP)
Based on a web search, https://bogdanz.me/work/diddu.html might be a working mirror of the proof of concept.

It appears to contain a 10MB long UTF-8 mess in both the og:title meta content and in a mailto: link.

I'd guess it's supposed to crash iOS apps by either posting that link if it displays links in a thumbnail element using og:title or otherwise by pasting the huge mailto link contained in the webpage, or perhaps only the e-mail address.

◧◩
2. hamand+ph[view] [source] 2018-01-18 16:55:26
>>devit+G8
Can confirm, just crashed my friends iPhone X. Required a hard reboot, was locked up completely.
[go to top]