mizzao 8 days ago

The "code execution" in PDF parsing is what enabled this legendary zero-click, zero-day exploit of iOS devices: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

1
kccqzy 8 days ago

That exploit is indeed legendary but the code execution involved is not JavaScript. In fact the iOS PDF renderer does not have JavaScript enabled.

saagarjha 7 days ago

Obviously a skill issue; a true hacker would re-enable it.