Posted by deepcore under Apple (No Respond)
Safari User-Assisted Applescript Exec Attack
Posted by deepcore under Apple (No Respond)
In versions of Mac OS X before 10.11.1, the applescript:// URL scheme is provided, which opens the provided script in the Applescript Editor. Pressing cmd-R in the Editor executes the code without any additional confirmation from the user. By getting the user to press cmd-R in Safari, and by hooking the cmd-key keypress event, a […]
Tags: Apple, ios, osxApple Security Advisory 2015-10-21-1
Posted by deepcore under Apple (No Respond)
Apple Security Advisory 2015-10-21-2
Posted by deepcore under Apple (No Respond)
Apple Security Advisory 2015-10-15-1
Posted by deepcore under Apple (No Respond)
Apple Safari 8.0.8 URI Spoofing
Posted by deepcore under Apple (No Respond)
Apple Security Advisory 2015-09-30-01
Posted by deepcore under Apple (No Respond)
Apple Security Advisory 2015-09-30-02
Posted by deepcore under Apple (No Respond)
Apple Security Advisory 2015-09-30-03
Posted by deepcore under Apple (No Respond)
Dropbox FinderLoadBundle OS X Local Root Exploit
Posted by deepcore under Apple (No Respond)
The setuid root FinderLoadBundle that was included in older DropboxHelperTools versions for OS X allows loading of dynamically linked shared libraries that are residing in the same directory. The directory in which FinderLoadBundle is located is owned by root and that prevents placing arbitrary files there. But creating a hard link from FinderLoadBundle to somewhere […]
Tags: Apple, ios, osx