• 12.01.26

    From Xor to Doom: Zero-click Attacks Exposed

    Prof. Shimon Schocken

    A zero-click attack is a cyberattack in which malicious software infects a device without any user interaction, by exploiting hidden software vulnerabilities. A well-known example is Pegasus, developed by NSO Group, whose use was publicly exposed in 2021. Following this exposure, Apple, Google, and Meta Platforms closed major security gaps in iOS, Android, and WhatsApp, and initiated legal action against NSO. At the same time, U.S. and European regulators introduced tighter controls that significantly improved the security of mobile devices worldwide. Technically, zero-click attacks rely on a sophisticated blend of classical memory-exploitation techniques, subtle abuses of seemingly harmless compression algorithms, and—most remarkably—the construction of a virtual computer inside the target device. Once this virtual machine is in place, the attacker gains full control of the target device. This talk explains how such attacks work, and shows their deep connection to Turing completeness and to the core ideas taught in our Nand to Tetris course.

הרצאות האורח בסדרת ההרצאות CS For Real ניתנות החל משנת 2015 ומועברות על ידי חוקרים מביה"ס וממוסדות שונים ועל ידי מרצים מחברות המובילות בתחומי הטכנולוגיה כגון : WIX, GOOGLE , MOBILEYE ועוד.


מטרתן הינה לקרב את הסטודנטים של תואר ראשון במדעי המחשב ל"עולם האמיתי" ולחשוף אותם בפני אנשים מעניינים, חברות, טכנולוגיות, מחקרים ואתגרים במדעי המחשב.

 

 

Since the year 2015 we offer guest lectures within CS For Real. The lectures are given by researchers from different schools and institutions and by lecturers from leading technology companies (e.g., Wix, Google, Mobileye etc.).


The purpose of those lectures is to bring undergraduate computer science students closer to "the real world". It exposes them to interesting people, companies, technologies, research and other challenges within computer science.