Now if it was a true feature phone… good luck sideloading spyware. You’d have to disassemble the phone and mount the chips in an EEPROM reader to get anywhere, and that’s not an effective remote exploit.
that’s dumb. it’s very likely just as vulnerable as androids. the modem’s software is full of decades legacy cruft and many security holes, and likely not properly separated from the mic, the ram or the storage
Said software resides in ROM - Read-Only Memory - and cannot be modified unless the chip is extracted from the phone and installed in a special EEPROM reader that permits/has the capability to write to the chip. The phone’s hardware literally lacks the electrical connections needed to write to that chip. Plus, these chips nearly always had so little extra room (as a cost-saving measure) that something as simple as saved phone numbers needed to be offloaded to the SIM card’s storage - from which it was impossible to run additional apps because, again, that functionality just didn’t exist.
And in many of these older feature phones, the in-memory footprint of actively running software was also well known, so RAM was limited (again, to save on costs) to handle only known apps, thereby leaving vanishingly little headroom and making an in-RAM exploit to piggyback in extra software equally difficult. Finally, most true feature phones didn’t have data connections, making it almost impossible to introduce data into memory.
About the only way data could get in would have been via SMS, and a feature phone has none of the SMS capabilities of modern phones - they could only display an SMS payload as raw text, they had no functionality to interact with that payload in any way, making zero-click exploits equally impossible.
even if it is actually in read only memory (it is not in smartphones), that does not matter if a vulnerability grants remote code execution ability. it all happens in RAM. it is wiped with a power cycle but the attacker can just reinfect your phone.
to the SIM card’s storage - from which it was impossible to run additional apps because, again, that functionality just didn’t exist.
SIM cards support apps. have been that way for a very long time.
Finally, most true feature phones didn’t have data connections, making it almost impossible to introduce data into memory.
calls and sms are data, with a right vulnerability they can be used to deliver a payload
they could only display an SMS payload as raw text
same with modern phones, and yet attacks are delivered through them, somehow.
that’s dumb. it’s very likely just as vulnerable as androids. the modem’s software is full of decades legacy cruft and many security holes, and likely not properly separated from the mic, the ram or the storage
Said software resides in ROM - Read-Only Memory - and cannot be modified unless the chip is extracted from the phone and installed in a special EEPROM reader that permits/has the capability to write to the chip. The phone’s hardware literally lacks the electrical connections needed to write to that chip. Plus, these chips nearly always had so little extra room (as a cost-saving measure) that something as simple as saved phone numbers needed to be offloaded to the SIM card’s storage - from which it was impossible to run additional apps because, again, that functionality just didn’t exist.
And in many of these older feature phones, the in-memory footprint of actively running software was also well known, so RAM was limited (again, to save on costs) to handle only known apps, thereby leaving vanishingly little headroom and making an in-RAM exploit to piggyback in extra software equally difficult. Finally, most true feature phones didn’t have data connections, making it almost impossible to introduce data into memory.
About the only way data could get in would have been via SMS, and a feature phone has none of the SMS capabilities of modern phones - they could only display an SMS payload as raw text, they had no functionality to interact with that payload in any way, making zero-click exploits equally impossible.
even if it is actually in read only memory (it is not in smartphones), that does not matter if a vulnerability grants remote code execution ability. it all happens in RAM. it is wiped with a power cycle but the attacker can just reinfect your phone.
SIM cards support apps. have been that way for a very long time.
calls and sms are data, with a right vulnerability they can be used to deliver a payload
same with modern phones, and yet attacks are delivered through them, somehow.