Published on: 27 September 2017
Multiple vulnerabilities are found in Apple and Android devices built upon Broadcom BCM4355C0 model of wireless chipset. An attacker could exploit the vulnerabilities via a Wi-Fi connection without special permissions required.
Reports indicate that the proof-of-concept exploit code is available on the Internet.
A successful attack could lead to arbitrary code execution.
Users are advised not to connect mobile devices to suspicious Wi-Fi networks at all time.
https://support.apple.com/en-hk/HT208143
https://bugs.chromium.org/p/project-zero/issues/detail?id=1289
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11120
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11121