> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?
Not to be smart -- but how else would invites work?
Zero-Click Calendar invite vulnerability chain in macOS
131–140 of 166 posts
Re: Zero-Click Calendar invite vulnerability chain in macOS
#132Earlier quoted context omitted.
I want to say again that I'm not making this point by way of a first-principles derivation of what's going on. I know for a fact that the norm in large bounty programs is to incentivize payouts. I don't know that for sure about Apple's program, but it seems extraordinarily unlikely that they depart from this norm, given the care and ceremony with which they rolled this out (much later than other big tech firms). None…
The bounty cost is not relevant for the company, but what about admitting liability?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#133Earlier quoted context omitted.
Neither of the above examples would come from people in my company.
"others who I work with who were responsible for bringing me into it" sounded to me like people at your company, who I assumed would be able to add you to the meetings. I guess I might have been mistaken
Re: Zero-Click Calendar invite vulnerability chain in macOS
#134Earlier quoted context omitted.
> since it requires sending a calendar invite and clicking on the attachment. I thought it was a zero click exploit? As for being interested in iCloud and photos, is the argument that the people they’re looking to attack are unlikely to use iCloud? Cause otherwise getting photos and potentially email access seems quite valuable.
The bigger thing here I think is that the target platform is macOS. An important detail to internalize about major grey market buyers of vulnerabilities: they tend not to stockpile; every vulnerability they buy they need to maintain, and there's not much benefit to maintaining vulnerabilities you aren't going to use. There is, how should we put this, probably not a whole lot of scarcity in macOS RCE vulnerabilities?…
No idea what portion non-western journalists use Macs.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#135Earlier quoted context omitted.
I think suspicion of bug bounties even from organizations who would clearly benefit the nost from doing them right are well founded and you are over simplifying the situation. Every organization includes a mess of situations where the overall best interest of the organization no longer comes through. Groups and individuals don't want to admit mistakes both personal and in wider senses and have alliances, competitions…
Bug bounty programs aren't whistleblower programs.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#136Earlier quoted context omitted.
The bigger thing here I think is that the target platform is macOS. An important detail to internalize about major grey market buyers of vulnerabilities: they tend not to stockpile; every vulnerability they buy they need to maintain, and there's not much benefit to maintaining vulnerabilities you aren't going to use. There is, how should we put this, probably not a whole lot of scarcity in macOS RCE vulnerabilities?…
I'd assume most western journalists would have Mac laptops. No idea what portion non-western journalists use Macs.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#137Earlier quoted context omitted.
Bug bounty programs aren't whistleblower programs.
AP is saying they can suffer from the same corporate politics.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#138Earlier quoted context omitted.
AP is saying they can suffer from the same corporate politics.
That doesn't make sense, because bounty programs can't punish vulnerability researchers other than not awarding bounties, and whistleblower programs can punish whistleblowers. I got what that comment was trying to say, but, no.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#139Earlier quoted context omitted.
That doesn't make sense, because bounty programs can't punish vulnerability researchers other than not awarding bounties, and whistleblower programs can punish whistleblowers. I got what that comment was trying to say, but, no.
It becomes corporate politics when 'blame' is assigned to the team responsible for the bug.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#140Earlier quoted context omitted.
No, it's because Apple's 'product security' team that investigates and pays out bug bounties is horribly mismanaged and ineffective. It was recently moved from the SWE program office to SEAR (security engineering & arch), and the manager was recently shown the door and went to AirBNB. The team members are mostly new college grads (ICT2's and 3's) who wouldn't pass a coding interview elsewhere in the company, and most…
I have no idea about how well the bounty program at Apple is managed, so, without affirming this, I acknowledge this is another plausible explanation: it's just an understaffed team that needs to get its act together. The only crusade I'm on is against the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false, like, the opposite of the truth. I think it's valuable for…
Eh, it's likely usually true, but I've worked for a company which was attracted to the bounty program idea mainly for the optics and very much did push back on/was very reluctant to pay out on bounties.
And when I say "for the optics" I mean not only for the company being able to boast about having a bounty program but also the executive in question having something for his quarterly report. Having it not be too expensive was definitely part of the deal.
Needless to say this was a terrible company with terrible leadership, but it's a data point...