Recall that at this point however I'm using a 2.

  • A more pragmatic view of reality is that whilst the security and product teams do want to continue our research, and do have many more resources, the one important resource they lack is time.

  • Helpfully if the memory doesn't meet those requirements as long as the virtual address was mapped and readable the code won't crash so we have some leeway.

Fortunately it was fairly easy to avoid triggering it, but my exploit continued to panic the target device in a multitude of ways.

  • They aren't starting with absolutely no clue how bluetooth or wifi work.

  • In this case of course trying to read from an address like 0x4141414141414141 will almost certainly cause a kernel panic, so we've still got more work to do.

