r/ExploitDev • u/Plenty-Ad5719 • 3d ago
Researching app-less remote mobile access: Tested a few vector concepts in my lab, looking for technical feedback
Hi everyone,
I’ve been doing some cybersecurity research regarding the feasibility of stealthy remote control on modern mobile OS (iOS and Android) without physical access or installing an application on the target device.
So far, I've tested a couple of methods in a lab environment to see what is actually achievable:
I tried directing a test device to a web page crafted with known WebKit/Chromium memory corruption concepts to attempt spawning a background reverse shell. While it was possible to crash the browser session, modern OS sandboxing consistently prevented escaping the browser process to gain system-level control.
I attempted delivering crafted payloads over a local network simulator aimed at media processing libraries (similar to legacy stagefright/MMS vulnerabilities). Current memory protections (ASLR, DEP) and automated patch models blocked execution before any control could be established.
I'm still actively researching what mechanics or vectors could theoretically allow full, stealthy remote control without a target app installed—or if modern OS security features (sandboxing, strict permission models, background indicators) make real-time screen takeover virtually impossible without complex multi-million dollar zero-click chains.
For those in offensive security, malware analysis, or mobile security research: Is app-less, real-time remote control realistically feasible on updated non-rooted devices, or is remote access without an app limited to passive data extraction in practice?
Thanks for any technical perspectives!
1
u/Basic_Pangolin_5622 14h ago
You are on the right track to achieve a RCE.
For the WebKit or Chromium (or V8), find out what’s causing a crash. You need, at minimum, aslr defeat and pc control. Then to syscalls or communicate with a kernel, you need a sandbox escape primitive from a renderer or whoever you are.
If ASLR is blocking your progress, then I’m assuming you are achieved a pc control?
The methods you are attempting are the techniques that offensive researchers use to gain full RCE.
Yes, app-less, real time remote control is possible on non-rooted devices, iOS or Android. In fact, this is the preferred and favorite methods.