Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

21–30 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#21
post #19

> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#22
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

I, in UK, book things on Eventbrite, they email you with a calendar invite. Same with other booking systems for events IIRC. You can probably add people to an invitation? Maybe if you can exploit such a system then people would have them in their whitelist in any case?

A little adjacent to your question but relevant enough I think.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#23
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

HR / Recruiter setting up interviews? The person doing the inviting might be different from previous calls/emails.

Customer meetings I get invited to often come from someone I’ve never dealt with before, but include others who I work with who were responsible for bringing me into it.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#24

Does Lockdown Mode prevent this?

Totally speculating, but I’d hope so. After all the prior zero-click image attachment related exploits, which I think lockdown mode was built to address, I’d figure all files are treated in that manner.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#25
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

This is a regular part of the recruiting process, where you may start chatting in LinkedIn and then get an invite on your email.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#26
It sure is a good thing that Apple has fixed all these, and has put out patches for all effected versions, since they care about their users' privacy, right? Right?

I know Apple has now switched to 10 years for MacOS, and 7ish years of iOS, but I hope the EU passes some laws to make this a requirement, rather than something a company can choose to provide or not.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#27
post #2

Great write up. Any guess on the bounty amount for this zero-click vulnerability, with a 5 step exploit chain for macOS?

Dude likely could have sold this to malicious threat actors for 6 figures.

Weird that it's been 2 years now and Apple still hasn't paid anything.

Really highlights why people might tend to gravitate towards that route instead of going thru the legit bug bounty process.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#28
post #14

Earlier quoted context omitted.

Definitely not received yet. > 2024–09–12: Still no bounty [...] . Apples bounty payouts are ball-parked here: https://security.apple.com/bounty/categories/

Relevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000

$5?!? Really incentivizing selling it on the black market.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#29
post #26

It sure is a good thing that Apple has fixed all these, and has put out patches for all effected versions, since they care about their users' privacy, right? Right? I know Apple has now switched to 10 years for MacOS, and 7ish years of iOS, but I hope the EU passes some laws to make this a requirement, rather than something a company can choose to provide or not.

Yes? As the OP states:

2022–08–08: Arbitrary file write and delete in Calendar sandbox reported

2022–10–24: (No CVE) fixed in macOS Monterey 12.6.1 and Ventura 13 (Ventura beta3 was vulnerable)

Re: Zero-Click Calendar invite vulnerability chain in macOS

#30
post #26

It sure is a good thing that Apple has fixed all these, and has put out patches for all effected versions, since they care about their users' privacy, right? Right? I know Apple has now switched to 10 years for MacOS, and 7ish years of iOS, but I hope the EU passes some laws to make this a requirement, rather than something a company can choose to provide or not.

Apple can increase those times because that's how long it'll take them to patch issues like these.
Post reply on HN