Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

31–40 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#31
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

I've received Apple Calendar invites containing Chinese characters from individuals I've never heard of. I deleted them, but just receiving them was a bit alarming.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#33
post #27
post #2

Great write up. Any guess on the bounty amount for this zero-click vulnerability, with a 5 step exploit chain for macOS?

Dude likely could have sold this to malicious threat actors for 6 figures. Weird that it's been 2 years now and Apple still hasn't paid anything. Really highlights why people might tend to gravitate towards that route instead of going thru the legit bug bounty process.

Does it work on an iPhone? If not, you're probably not selling it for 6 figures, or even 5.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#34

Earlier quoted context omitted.

Relevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000

$5?!? Really incentivizing selling it on the black market.

Surely depends on the severity. If the attacker is only able to read if you prefer dark mode from a calendar invite then nobody will pay a lot.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#35

> An attacker can send malicious calendar invites to the victim that include file attachments...Before fixes were done, I was able to send malicious calendar invitations to any Apple iCloud user and steal their iCloud Photos without any user interaction. What's the scope of this? Can anyone on macOS anywhere really just send random invites to anyone else who uses icloud? Who would even want that?

Is g cal not the same?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#36

Earlier quoted context omitted.

Relevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000

$5?!? Really incentivizing selling it on the black market.

Which black market? Who is buying it? The reason they quote such a huge range of prices is that there is a huge range of utility across different exploits, and many of them aren't worth much at all, including some that seem ultra-powerful on the tin.

Keep in mind also that the economics of bug bounties are different than those of the "black market". Bounties quote lower prices because they're offering assured payouts, often with lower exploit proof and enablement requirements. They're not actually apples and oranges.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#38

Earlier quoted context omitted.

Relevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000

$5?!? Really incentivizing selling it on the black market.

If only Apple had a better cash-flow situation so they could pay out more. Alas...

Re: Zero-Click Calendar invite vulnerability chain in macOS

#39
Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research; not paying out legitimate bounties works against that goal. Nobody on the vendor side is spending their own money. The sums involved are not meaningful to the company. Generally, the team members running the program are actually incentivized to pay out more bounties, not less.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#40

Earlier quoted context omitted.

$5?!? Really incentivizing selling it on the black market.

Surely depends on the severity. If the attacker is only able to read if you prefer dark mode from a calendar invite then nobody will pay a lot.

I am not sure what Apple defines as “sensitive data”, but surely that would be something more tasty than user UI configuration.
Post reply on HN