The attack makes use of previously disclosed critical vulnerabilities in Apple's web browser and iOS.
A Chinese security researcher has published what he claims is a proof-of-concept exploit that would allow a remote attacker to jailbreak an iPhoneX – allowing them to gain access to a victim's data, processing power, and more.
Qixun Zhao of Qihoo 360 created the exploit, which he calls “Chaos,” around the revealing critical vulnerabilities in Apple Safari and iOS, which Apple patched this week with iOS 12.1.3.
Phones running iOS 12.1.2 and earlier are still vulnerable to Chaos, which exploits two security vulnerabilities first reported at the TianfuCup hacking competition last November: A memory corruption flaw in Apple's Safari WebKit (CVE-2019-6227) and a use-after-use memory leak issue in the iOS kernel (CVE-2019-6225).

The first vulnerability would allow an attacker to create a malicious web page using the Safari browser , containing scripts to execute arbitrary code on a targeted device. Once this code is executed, the attacker can use the second flaw to gain elevated privileges and secretly install a malicious application of their choosing.
This application could be any kind of malware, built for eavesdropping or other espionage, ad fraud, SMS, cryptography, or a range of other malicious activities, the researcher said.
Does the attack have a social aspect? Victims would need to be lured into visiting the malicious website via Safari on their iPhone Xs.
While the researcher published a PoC video, he chose not to publish the jailbreak code itself, given the potentially large scale of the attack.
“I will not be releasing the exploit code, if you want to jailbreak, you will have to complete the exploit code yourself or wait for it to be released to the jailbreak community,” he said in a technical description of the exploit on Wednesday. “At the same time, I will not be releasing the post-exploit exploit details, as that is handled by the jailbreak community.”
