On a device with lockdown mode enabled, the user’s iPhone blocks an attempted HomeKit invitation. Source: Citizen Lab
Since Lockdown Mode’s debut in iOS 16, its ability to resist sophisticated spyware such as Pegasus had not yet been publicly demonstrated. Citizen Lab has now reported the first known case showing that the feature could detect and alert a user to an attempted attack.
What is PWNYOURHOME?
PWNYOURHOME is a zero-click exploit chain designed to target iPhones running iOS 15 or iOS 16. It appears to operate in two stages: the first involves HomeKit’s homed process, and the second targets iMessage’s MessagesBlastDoorService. Despite the use of HomeKit for the attack, it did not require the target to have previously set up a Home in HomeKit.
Citizen Lab examined logs from several devices compromised with PWNYOURHOME. On one, investigators found an attacker’s email address in the HomeKit database. The logs indicated that the address had been added about eight minutes before Pegasus activity was recorded, and also showed that an iMessage attachment had been deleted. On other devices, researchers observed crashes in homed during the HomeKit stage and in MessagesBlastDoorService after the phone received PNG images through iMessage.
Lockdown Mode restricts invitations from unknown senders, including Home invitations, and can notify users when it blocks one. Because it was enabled in this case, the device provided a notification into the unexpected communication through HomeKit. Spyware vendors are undoubtedly testing and modifying their payloads to avoid triggering user notifications, so the absence of an alert should not be taken as confirmation that no attack was attempted.
The investigation by Citizen Lab prompted changes to HomeKit in iOS 16.3.1. Apple added checks to reject certain HomeKit messages unless they came from a plausible source.
A full readout of Citizen Lab’s technical report can be found here.