My theory on how the webp 0day was discovered (BLASTPASS) @LiveOverflow
My theory on how the webp 0day was discovered (BLASTPASS)  @LiveOverflow
Uploaded September 2024 | Updated September 2026, 2 weeks ago
I have spent many hours looking at the webp vulnerability used in the 0day attack against iPhones. In the past videos we have seen why fuzzers have a hard time finding the issue, so I wanted to understand how this was discovered. And I think I have a good theory!

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Part 1: Huffman Tables youtu.be/lAyhKaclsPM
Part 2: Fuzzing libwebp youtu.be/PJLWlmp8CDM

Sources:
citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild
googleprojectzero.blogspot.com/2019/08/the-fully-remote-attack-surface-of.html
googleprojectzero.blogspot.com/2020/01/remote-iphone-exploitation-part-1.html
googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html
github.com/seemoo-lab/frida-scripts/blob/main/scripts/libdispatch.js
googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html
citizenlab.ca/2023/04/nso-groups-pegasus-spyware-returns-in-2022
github.com/libjxl/libjxl/blob/4b9dbde293f7f282b6952a02340300abfca2b184/lib/jxl/huffman_table.cc#L51
github.com/webmproject/libwebp/blob/7861947813b7ea02198f5d0b46afa5d987b797ae/src/dec/vp8l_dec.c#L86C3-L86C76
github.com/Tencent/mars/blob/9ab46e19ed3d4fcafe9d0de4b36547321f5ead83/mars/comm/windows/zlib/inftrees.h#L41
github.com/google/brunsli/blob/master/c/enc/jpeg_huffman_decode.h#L20

CHAPTERS
00:00 - Intro
01:18 - The iPhone Remote Attack Surface
02:49 - Targeting iMessage
04:04 - Dangerous Parsing / BlastDoor
06:53 - Image I/O and libwebp
08:11 - A Pattern of Image Vulnerabilities
09:28 - Huffman Tables are Everywhere!
10:50 - My Theory: known issue with enough.c
13:50 - Outro

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#SecurityResearch #iOS #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
My theory on how the webp 0day was discovered (BLASTPASS)Root Cause Analysis With AddressSanitizer (ASan) | Ep. 06Script Gadgets! Google Docs XSS Vulnerability WalkthroughThe Same Origin Policy - Hacker HistoryDEF CON & Black Hat Trip 2024Why Hackers Love the Number 1,094,795,585Why MissingNo Multiplies Items!Discussing Heap Exploit Strategies for sudo - Ep. 09Introduction to Docker for CTFsWhat is a Protocol? (Deepdive)Failed DOM Clobbering Research - All The Little Things 1/2 (web) Google CTF 2020Local Root Exploit in HospitalRun Software
LiveOverflow |

My theory on how the webp 0day was discovered (BLASTPASS)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER