Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

131–140 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#131
post #19

> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?

Not to be smart -- but how else would invites work?

There are possible safeguards -- only allowing invites if you are on each other's contact lists, for example, or the same domain, or something else. Apple had a big problem with Calendar spam that they have not really fixed.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#132
post #130

Earlier quoted context omitted.

I want to say again that I'm not making this point by way of a first-principles derivation of what's going on. I know for a fact that the norm in large bounty programs is to incentivize payouts. I don't know that for sure about Apple's program, but it seems extraordinarily unlikely that they depart from this norm, given the care and ceremony with which they rolled this out (much later than other big tech firms). None…

The bounty cost is not relevant for the company, but what about admitting liability?

Not a real concern.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#133
post #102

Earlier quoted context omitted.

Neither of the above examples would come from people in my company.

"others who I work with who were responsible for bringing me into it" sounded to me like people at your company, who I assumed would be able to add you to the meetings. I guess I might have been mistaken

Depends on who is running the meeting. If the customer is hosting, the others I work with will provide my email to the customer so they can add me to the invite.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#134
post #90

Earlier quoted context omitted.

> since it requires sending a calendar invite and clicking on the attachment. I thought it was a zero click exploit? As for being interested in iCloud and photos, is the argument that the people they’re looking to attack are unlikely to use iCloud? Cause otherwise getting photos and potentially email access seems quite valuable.

The bigger thing here I think is that the target platform is macOS. An important detail to internalize about major grey market buyers of vulnerabilities: they tend not to stockpile; every vulnerability they buy they need to maintain, and there's not much benefit to maintaining vulnerabilities you aren't going to use. There is, how should we put this, probably not a whole lot of scarcity in macOS RCE vulnerabilities?…

I'd assume most western journalists would have Mac laptops.

No idea what portion non-western journalists use Macs.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#135

Earlier quoted context omitted.

I think suspicion of bug bounties even from organizations who would clearly benefit the nost from doing them right are well founded and you are over simplifying the situation. Every organization includes a mess of situations where the overall best interest of the organization no longer comes through. Groups and individuals don't want to admit mistakes both personal and in wider senses and have alliances, competitions…

Bug bounty programs aren't whistleblower programs.

AP is saying they can suffer from the same corporate politics.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#136
post #90

Earlier quoted context omitted.

The bigger thing here I think is that the target platform is macOS. An important detail to internalize about major grey market buyers of vulnerabilities: they tend not to stockpile; every vulnerability they buy they need to maintain, and there's not much benefit to maintaining vulnerabilities you aren't going to use. There is, how should we put this, probably not a whole lot of scarcity in macOS RCE vulnerabilities?…

I'd assume most western journalists would have Mac laptops. No idea what portion non-western journalists use Macs.

Again I'll say I'm not axiomatically reconstructing the relative values of exploits on different platforms, and observe that this is something you can go research and learn about. No, macOS exploits are not as valuable as iOS exploits.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#137

Earlier quoted context omitted.

Bug bounty programs aren't whistleblower programs.

AP is saying they can suffer from the same corporate politics.

That doesn't make sense, because bounty programs can't punish vulnerability researchers other than not awarding bounties, and whistleblower programs can punish whistleblowers. I got what that comment was trying to say, but, no.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#138

Earlier quoted context omitted.

AP is saying they can suffer from the same corporate politics.

That doesn't make sense, because bounty programs can't punish vulnerability researchers other than not awarding bounties, and whistleblower programs can punish whistleblowers. I got what that comment was trying to say, but, no.

It becomes corporate politics when 'blame' is assigned to the team responsible for the bug.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#139

Earlier quoted context omitted.

That doesn't make sense, because bounty programs can't punish vulnerability researchers other than not awarding bounties, and whistleblower programs can punish whistleblowers. I got what that comment was trying to say, but, no.

It becomes corporate politics when 'blame' is assigned to the team responsible for the bug.

The preceding comment, I could follow. This one I cannot. But I think we're doing the same thing that's happening all over this thread, and trying to axiomatically derive how these programs work. I'm not doing that; I (like a lot of people) have direct knowledge of them. It's not much of a secret.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#140
post #74

Earlier quoted context omitted.

No, it's because Apple's 'product security' team that investigates and pays out bug bounties is horribly mismanaged and ineffective. It was recently moved from the SWE program office to SEAR (security engineering & arch), and the manager was recently shown the door and went to AirBNB. The team members are mostly new college grads (ICT2's and 3's) who wouldn't pass a coding interview elsewhere in the company, and most…

I have no idea about how well the bounty program at Apple is managed, so, without affirming this, I acknowledge this is another plausible explanation: it's just an understaffed team that needs to get its act together. The only crusade I'm on is against the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false, like, the opposite of the truth. I think it's valuable for…

> the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false

Eh, it's likely usually true, but I've worked for a company which was attracted to the bounty program idea mainly for the optics and very much did push back on/was very reluctant to pay out on bounties.

And when I say "for the optics" I mean not only for the company being able to boast about having a bounty program but also the executive in question having something for his quarterly report. Having it not be too expensive was definitely part of the deal.

Needless to say this was a terrible company with terrible leadership, but it's a data point...

Post reply on HN