Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

41–50 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#41
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

Project manager from other team arranging a cross team meeting?

Secretary office admin doing their job?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#42
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

I'd want to whitelist specific people before they could send me a calendar invite. Every other invite request should never reach my device. If I don't even know you, why would I want your invites anyway?

Because you work with people outside of your company, support, vendors, sales people etc.

Boss: Why aren't you in the meeting with our vendor to upgrade our X system?

You: Oh I whitelist all my invites. You see, I am thinking about security and don't want to receive invites from someone I don't know.

Boss: Clear your desk, security will walk you out.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#43

Earlier quoted context omitted.

I'd want to whitelist specific people before they could send me a calendar invite. Every other invite request should never reach my device. If I don't even know you, why would I want your invites anyway?

Because you work with people outside of your company, support, vendors, sales people etc. Boss: Why aren't you in the meeting with our vendor to upgrade our X system? You: Oh I whitelist all my invites. You see, I am thinking about security and don't want to receive invites from someone I don't know. Boss: Clear your desk, security will walk you out.

Or the much more sensible, and MSFT way of handling it (in outlook)

ExternalUser: Hello here is a calendar invite I would like you to attend, please confirm or deny

User: Thank you, now I can verify the request and choose to add this to my calendar or not

Re: Zero-Click Calendar invite vulnerability chain in macOS

#44
post #21

Earlier quoted context omitted.

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

This is a regular part of the recruiting process, where you may start chatting in LinkedIn and then get an invite on your email.

If the recruiter doesn't ask me first (or I don't agree to a meeting), this is called "spam", and I would be happy for the system to just not allow it.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#45
post #21

Earlier quoted context omitted.

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

HR / Recruiter setting up interviews? The person doing the inviting might be different from previous calls/emails. Customer meetings I get invited to often come from someone I’ve never dealt with before, but include others who I work with who were responsible for bringing me into it.

I think there's a pretty big gap between "people at my company are allowed to add things to my calendar" and "random stranger anywhere in the world can add things to my calendar".

Re: Zero-Click Calendar invite vulnerability chain in macOS

#46
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

Unless the implication is that the author of this point is misrepresenting things, I'm struggling to think of what "very good reason" there could be when there's a clear record of someone reporting a bug well before it's fixed. At best, it seems like typical slow bureaucracy, which I don't think is a particularly good reason. There's no reason it should take over a year for someone to approve something like this if the company actually incentivized it. Your logic might be sound, but it's hard for me to look at a situation like this and think "company is either stingy or overly bureaucratic like companies overwhelmingly tend to be in almost every other circumstance" is less likely than "company has legitimate reason not to pay out a bounty that ostensibly has been fulfilled". It just seems way more plausible that the incentives that happen pretty much everywhere else have bled into this domain, assuming the author is accurately describing the events.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#47
Thankfully I don't use iCloud Photo Library, but it's both weird to learn that when the photo library location has been changed, the new location does not get any protection. I would have expected the exploit to fail after setting /var/tmp/mypictures/Syndication.photoslibrary as the system photo library and opening Photos because the Photos app should know to protect this directory.

I just did a quick test on my Sonoma 14.6.1 system. Hold the Option key while opening Photos to create a new photo library in ~/Pictures; then use an app without full disk access permission and without photo permission to access that folder. That app was denied access. Then do the same except the new photo library is created in /tmp. That same app is allowed access. This behavior is baffling and inconsistent.

If Apple really intends to support the feature of allowing the user to relocate their photo library to anywhere on the file system, they need to apply the protection properly.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#48
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

I recently booked a haircut that sent me a calendar invite via email after booking it. I had never interacted with that email before, but I accepted the invite.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#50
post #41
post #21

Earlier quoted context omitted.

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

Project manager from other team arranging a cross team meeting? Secretary office admin doing their job?

In-org usually has the whole domain white-listed and the whole organization would normally be auto-synced to your contacts.
Post reply on HN