So, another IOMFB vulnerability was exploited ITW (15.0.2). I bindiffed the patch and built a POC. And, because it's a great bug, I just finished writing a short blogpost with the tech details, to share this knowledge :) Check it out! https://saaramar.github.io/IOMFB_integer_overflow_poc/…
Definitely possible :) As I wrote, I only tested it on iPhone X (physical device) and iPhone 11 Pro (virtual device), 14.7.1-15.0.1. I didn't check iPhone 12 :)