Jump to content
Facebook Twitter Youtube

[Software] Safari flaws let hackers spy on your Mac and iPhone


#REDSTAR ♪ ♫
 Share

Recommended Posts

They could take control of your webcam and mic

 

QS6LDwqwLmfpyXjoG5sRPU-480-80.jpg

 

 

 

Apple products and services are generally considered to be secure, but flaws in the Safari browser could damage that reputation. 

 

Hackers found a way to take control of a Mac or iPhone's microphones and cameras by exploiting Safari browser bugs. The problem stems from permissions Safari asks users to grant to certain websites, Ryan Pickren, the security researcher who disclosed the flaw to Apple, explained to Wired. 

 

Using a malicious link, attackers could trick users into opening a website that would disguise itself as one that was already granted microphone and camera permissions. The flawed Safari browser isn't smart enough to know it was a fake, so the browser would hand over mic and camera access to the malicious site and give bad actors the ability to spy on you.

 

The reason Safari couldn't tell a fake site from a real one has to do with how the browser treats URL variations -- https://www.example.com, http://example.com, and fake://example.com -- as part of the same website.

 

"I just kind of hammered the browser with really weird cases until Safari got confused and gave an origin that didn’t make sense," Pickren told Wired. "And eventually the bugs could all kind of bounce from one to the next. Part of this is that some of the bugs were really, really old flaws in the WebKit core from years ago."

 

Apple fortunately patched these vulnerabilities after Pickren brought them to the company's attention. Pickren told Apple about seven vulnerabilities in mid-December and they were validated the next day. Patches were released in January and March updates and Pickren was rewarded a cool $75,000 as part of Apple's bug bounty program.

Apple is fortunate that Pickren disclosed these problems when he did. If it were any later, the flaws might have surfaced at a time when more people are working from home than ever before. The global workforce's reliance on video conferencing apps that need access to your mic and camera has skyrocketed during the coronavirus pandemic. By patching those issues early, Apple may have dodged the type of security nightmare Zoom currently finds itself in. 

  • I love it 1
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

WHO WE ARE?

CsBlackDevil Community [www.csblackdevil.com], a virtual world from May 1, 2012, which continues to grow in the gaming world. CSBD has over 70k members in continuous expansion, coming from different parts of the world.

 

 

Important Links