Researchers say a change in iOS 14.5 beta, which improves how iOS handles pointers, makes sandbox escapes and “0-click” attacks much harder to pull off
Multiple exploit developers tell Motherboard an upcoming change in iOS could make zero-click exploits harder to pull off.
Context & Ripple Effects
The iOS 14.5 beta change lands after a run of zero-click iPhone attacks: the zero-click AWDL exploit detailed in December 2020, now patched, and the two actively exploited iOS 0-days found in April 2020, which included a remote zero-click flaw in Mail and had persisted since at least iOS 6.
Those attacks typically needed a chain: a way in, then a sandbox escape to reach data and hardware. By hardening pointer handling, Apple is attacking the second link of that chain — which is why exploit developers, not just attackers, are the ones flagging how much harder their work just got.
First-order effects
- Exploit developers lose their cheapest sandbox-escape techniques on iOS 14.5, raising the cost and time needed to build working zero-click chains against current iPhones.
Second-order effects
- Attackers who previously chained a zero-click entry with an easy escape — the pattern behind the AWDL and Mail flaws — must buy or develop new escape primitives, pushing demand toward the still-unpatched or undiscovered bugs that remain.
Third-order effects
- If Apple keeps raising the cost of each chain link, the zero-click market shifts toward rarer, pricier bugs and longer development cycles — and as Trellix's later NSPredicate sandbox bugs built on ForcedEntry showed, researchers will keep testing whether the hardening actually holds.
The trend: Apple is responding to a decade of zero-click iPhone attacks by hardening iOS internals so that exploit chains fail at the sandbox-escape stage, forcing attackers to pay more per successful breach.