Earlier quoted context omitted.
Not to be smart -- but how else would invites work?
How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?
Zero-Click Calendar invite vulnerability chain in macOS
31–40 of 166 posts
Re: Zero-Click Calendar invite vulnerability chain in macOS
#32Don’t love the bounty state here — security researchers, is it typical to wait this long with Apple or other FAANG type companies?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#33Great write up. Any guess on the bounty amount for this zero-click vulnerability, with a 5 step exploit chain for macOS?
Dude likely could have sold this to malicious threat actors for 6 figures. Weird that it's been 2 years now and Apple still hasn't paid anything. Really highlights why people might tend to gravitate towards that route instead of going thru the legit bug bounty process.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#34Earlier quoted context omitted.
Relevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000
$5?!? Really incentivizing selling it on the black market.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#35> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#36Earlier quoted context omitted.
Relevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000
$5?!? Really incentivizing selling it on the black market.
Keep in mind also that the economics of bug bounties are different than those of the "black market". Bounties quote lower prices because they're offering assured payouts, often with lower exploit proof and enablement requirements. They're not actually apples and oranges.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#37And yet Apple still hasn't paid up. Need to just start selling these to people who will use them at this point.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#38Re: Zero-Click Calendar invite vulnerability chain in macOS
#39Re: Zero-Click Calendar invite vulnerability chain in macOS
#40Earlier quoted context omitted.
$5?!? Really incentivizing selling it on the black market.
Surely depends on the severity. If the attacker is only able to read if you prefer dark mode from a calendar invite then nobody will pay a lot.