IPhone Remotely Captive

Since June, I’ve been subject to some sort of privilege escalation exploit on my iPhone which has spread to my MacBook Air. Before I hear the usual “this can’t happen on an iPhone” or “why do you think that”, these are the steps I have taken:

-redownloaded ios via iTunes 15 times

-deleted my old iCloud

-spoken to support and a genius professional in excess of 20 times without success (it’s not a hardware issue- but I believe it is possible once someone has the regulatory information it will repeatedly happen - a simply google search will tell you that.)


Each time i reset the phone, after a week it is able to change settings, stop me from doing certain things, disconnect my Bluetooth or any wifi at will and more things than I can describe. For the sake of brevity, I’ve attached some evidence and hope someone may be able to provide guidance. The first video is me setting up automation to let me know whenever an app is open and screen time reflecting app usage of apps I don’t have.

Thank you.


https://store-028.blobstore.apple.com/v01/FR/6659/5671/0000/15428062/Video_01.mov?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=MKIA0879Y5FEZQ0RYD6Z%2F20200829%2Fstore-028%2Fs3%2Faws4_request&X-Amz-Date=20200829T060219Z&X-Amz-Expires=15&X-Amz-SignedHeaders=host&X-Amz-Signature=f81a4d00d60068ad250c000f16250ecfb7f81e736f310924a6684bb8578c305e


Small piece of error log (please don’t say “logs are for devs”, I get it) that reflects a not real “exception” that occurred during sys_diagnose for the Feedback App.


{"bug_type":"288","timestamp":"2020-08-29 02:03:20.87 -0400","os_version":"iPhone OS 14.0 (18A5357e)","incident_id":"E65D1306-4071-4F3C-972A-83B7B6AC9A46"}

{

"build" : "iPhone OS 14.0 (18A5357e)",

"product" : "iPhone12,5",

"kernel" : "Darwin Kernel Version 20.0.0: Mon Aug 17 09:09:54 PDT 2020; root:xnu-7195.0.41~15\/RELEASE_ARM64_T8030",

"tuning" : {


},

"incident" : "E65D1306-4071-4F3C-972A-83B7B6AC9A46",

"crashReporterKey" : "61d34c9443773bffcc55c5f3fe237a465b323fb6",

"date" : "2020-08-29 02:03:20.86 -0400",

"reason" : "sysdiagnose (post-spindump) stackshot",

"frontmostPids" : [

60

],

"exception" : "0xbaaaaaad",

"absoluteTime" : 129318933411,

"memoryStatus" : {"compressorSize":13969,"compressions":200376,"decompressions":103202,"busyBufferCount":0,"pageSize":16384,"memoryPressure":false,"memoryPages":{"active":64531,"throttled":0,"fileBacked":57764,"wired":44425,"purgeable":4741,"inactive":61764,"free":43023,"speculative":2160}},

"processByPid" : {

"0" : {

"pid" : 0,

"residentMemoryBytes" : 175030272,

"timesDidThrottle" : 0,

"systemTimeTask" : 0,

"pageIns" : 0,

"pageFaults" : 3026,

"userTimeTask" : 29294.010933291,

"procname" : "kernel_task",

"copyOnWriteFaults" : 0,

"threadById" : {

"558" : {

"continuation" : [

0,

17123960

],

"userTime" : 8.4335751660000007,

"systemTime" : 0,

"id" : 558,

"basePriority" : 81,

"name" : "AppleSPU",

"user_usec" : 8433575,

"schedPriority" : 81,

"system_usec" : 0,

"state" : [

"TH_WAIT",

"TH_UNINT"


Posted on Aug 28, 2020 11:29 PM

Reply

Similar questions

4 replies

Aug 29, 2020 12:12 AM in response to Js0094a

the usual “this can’t happen on an iPhone” or “why do you think that”

Small piece of error log (please don’t say “logs are for devs”, I get it) that reflects a not real “exception” that occurred during sys_diagnose for the Feedback App.

Not sure there is a answerable technical support question in your post.


The statement this can't happen on an iPhone is usually after saying, "unless your have removed or impaired the iOS security features."


IMO, you should not really request or trust anybody here you interpret your logs. You'll get multiple conflicting answers and may cause more FUD for you.


a simply google search will tell you that.

You can also see the earth is indeed flat and that Elvis is still alive.


Finally, you mock the answers you see here, but you avoided answering why you think you have been compromised. Saying "privilege escalation exploit" means little to nothing.


Your video link goes nowhere.



Aug 29, 2020 7:29 AM in response to LACAllen

Totally fair, unacceptable to be rude and ask for help, apologies. I’m just exasperated and no one seems to be able to help. I have attached the screen time reflecting app usage of app as I don’t have. I reset the phone. This is the exploit meant:

https://bazad.github.io/2018/09/ios-privilege-escalation-via-crashing/


https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html?m=1


https://gtfobins.github.io/gtfobins/systemctl/


from some pieces of other error logs, it seems the phone exporting information constantly:

"MRE_BundleID" : "com.apple.Safari.PasswordBreachHelper",

"MRE_is64Bit" : true,

"MRE_ExecName" : "com.apple.Safari.PasswordBreachHelper",

"MRE_LimitValue" : 6,

"MRE_ExceptionType" : 4,

"MRE_LedgerPageTable" : 180728,

"MRE_ExecutionStack" : {

"MRE_ExecutionStack_BinaryImages" : {

"D99D09A3-B3A4-3862-9936-28BC3DD0BCBD" : {

"Identifier" : "com.apple.Safari.PasswordBreachHelper",

"BinaryInfoDwarfUUIDKey" : "D99D09A3-B3A4-3862-9936-28BC3DD0BCBD",

"BinaryInfoArchitectureKey" : "arm64e",

"ExecutablePath" : "\/System\/Library\/PrivateFrameworks\/SafariShared.framework\/XPCServices\/com.apple.Safari.PasswordBreachHelper.xpc\/com.apple.Safari.PasswordBreachHelper",




I realize it’s old but i believe that is what is occurring.



Aug 29, 2020 8:47 AM in response to Js0094a

Also used terminus to find this:

File "<console>", line 1, in <module>

/Users/holzschu/src/Xcode_iPad/network_ios/sources/bind9/lib/isc/unix/app.c:888: REQUIRE(isc_g_appctx.blocked) failed, back trace

#0 0x11479f138 in ??

#1 0x11479f0c4 in ??

#2 0x1147dabc0 in ??

#3 0x114801cf4 in ??

#4 0x1148c1994 in ??

#5 0x1147da7b0 in ??

#6 0x114801ae0 in ??

#7 0x102c7ddf0 in ??

#8 0x1dc1b5ca8 in ??

#9 0x1dc1be788 in ??

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

IPhone Remotely Captive

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.