Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

11–20 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#12

Super interesting, though I doubt they'll pay a bounty on something they've already fixed.

>though I doubt they'll pay a bounty on something they've already fixed.

CVE-2022–46723 was reported 2022-08-08 and fixed later on 2022-10-24, which the author of this post was credited by Apple for reporting.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#13
post #12

Super interesting, though I doubt they'll pay a bounty on something they've already fixed.

> though I doubt they'll pay a bounty on something they've already fixed. CVE-2022–46723 was reported 2022-08-08 and fixed later on 2022-10-24, which the author of this post was credited by Apple for reporting.

So he likely got the bounty, then, or will get it. Any idea how much it is?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#14
post #13
post #12

Earlier quoted context omitted.

> though I doubt they'll pay a bounty on something they've already fixed. CVE-2022–46723 was reported 2022-08-08 and fixed later on 2022-10-24, which the author of this post was credited by Apple for reporting.

So he likely got the bounty, then, or will get it. Any idea how much it is?

Definitely not received yet.

>2024–09–12: Still no bounty [...].

Apples bounty payouts are ball-parked here:

https://security.apple.com/bounty/categories/

Re: Zero-Click Calendar invite vulnerability chain in macOS

#15
post #14
post #13

Earlier quoted context omitted.

So he likely got the bounty, then, or will get it. Any idea how much it is?

Definitely not received yet. > 2024–09–12: Still no bounty [...] . Apples bounty payouts are ball-parked here: https://security.apple.com/bounty/categories/

Relevant section states:

> Zero-click unauthorized access to sensitive data $5,000 to $500,000

Re: Zero-Click Calendar invite vulnerability chain in macOS

#16
> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction.

What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#19

> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?

Not to be smart -- but how else would invites work?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#20
post #19

> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?

Not to be smart -- but how else would invites work?

I'd want to whitelist specific people before they could send me a calendar invite. Every other invite request should never reach my device. If I don't even know you, why would I want your invites anyway?
Post reply on HN