Oh for goodness sake, Apple is still parsing untrusted TrueType fonts using an old pile of C code in 2023.
TrueType is not that hard to parse in a safe language if you don't need hinting, folks (which is disabled on iOS). In fact I wrote most of that code a few years ago.
This iMessage exploit is crazy. TrueType vulnerability that has existed since the 90s, 2 kernel exploits, a browser exploit, and an undocumented hardware feature that was not used in shipped software:
securelist.com/operation-tri…