> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?
Not to be smart -- but how else would invites work?
Zero-Click Calendar invite vulnerability chain in macOS
21–30 of 166 posts
Re: Zero-Click Calendar invite vulnerability chain in macOS
#22Earlier quoted context omitted.
Not to be smart -- but how else would invites work?
How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?
A little adjacent to your question but relevant enough I think.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#23Earlier quoted context omitted.
Not to be smart -- but how else would invites work?
How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?
Customer meetings I get invited to often come from someone I’ve never dealt with before, but include others who I work with who were responsible for bringing me into it.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#24Does Lockdown Mode prevent this?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#25Earlier quoted context omitted.
Not to be smart -- but how else would invites work?
How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#26I know Apple has now switched to 10 years for MacOS, and 7ish years of iOS, but I hope the EU passes some laws to make this a requirement, rather than something a company can choose to provide or not.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#27Great write up. Any guess on the bounty amount for this zero-click vulnerability, with a 5 step exploit chain for macOS?
Weird that it's been 2 years now and Apple still hasn't paid anything.
Really highlights why people might tend to gravitate towards that route instead of going thru the legit bug bounty process.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#28Earlier quoted context omitted.
Definitely not received yet. > 2024–09–12: Still no bounty [...] . Apples bounty payouts are ball-parked here: https://security.apple.com/bounty/categories/
Relevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000
Re: Zero-Click Calendar invite vulnerability chain in macOS
#29It sure is a good thing that Apple has fixed all these, and has put out patches for all effected versions, since they care about their users' privacy, right? Right? I know Apple has now switched to 10 years for MacOS, and 7ish years of iOS, but I hope the EU passes some laws to make this a requirement, rather than something a company can choose to provide or not.
2022–08–08: Arbitrary file write and delete in Calendar sandbox reported
2022–10–24: (No CVE) fixed in macOS Monterey 12.6.1 and Ventura 13 (Ventura beta3 was vulnerable)
Re: Zero-Click Calendar invite vulnerability chain in macOS
#30It sure is a good thing that Apple has fixed all these, and has put out patches for all effected versions, since they care about their users' privacy, right? Right? I know Apple has now switched to 10 years for MacOS, and 7ish years of iOS, but I hope the EU passes some laws to make this a requirement, rather than something a company can choose to provide or not.