Zero-Click Calendar invite vulnerability chain in macOS
mikko-kenttala.medium.com
Zero-Click Calendar invite vulnerability chain in macOS
1–10 of 166 posts
Re: Zero-Click Calendar invite vulnerability chain in macOS
#2Great write up.
Any guess on the bounty amount for this zero-click vulnerability, with a 5 step exploit chain for macOS?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#3[deleted]
Re: Zero-Click Calendar invite vulnerability chain in macOS
#4Apple still not paying bounty or needs to be publicly reminded…
Re: Zero-Click Calendar invite vulnerability chain in macOS
#5Apple still not paying bounty or needs to be publicly reminded…
[deleted]
Re: Zero-Click Calendar invite vulnerability chain in macOS
#6Ah another way to mess with the quarantine flags, the other being: https://imlzq.com/apple/macos/2024/08/24/Unveiling-Mac-Secur...
Seems just way too many different systems have the ability to modify those flags.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#7Super interesting, though I doubt they'll pay a bounty on something they've already fixed.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#8Does Lockdown Mode prevent this?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#9Don’t love the bounty state here — security researchers, is it typical to wait this long with Apple or other FAANG type companies?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#10Super interesting, though I doubt they'll pay a bounty on something they've already fixed.
[deleted]