Apple addressed multiple macOS vulnerabilities in the Safari browser that allows threat actors to access users’ online accounts, microphone, and webcam last year.
The flaws were discovered by security researcher Ryan Pickren and he received a bounty of $100,500 for reporting these issues as part of Apple’s bug bounty program.
By exploiting a chain of security issues with iCloud Sharing and Safari 15, it enables the attacker to hijack the multimedia permission and gain “full access to every website ever visited by the victim” in Safari, including Gmail, iCloud, Facebook, and PayPal accounts.
The bugs reside in the iCloud file-sharing mechanism named ShareBear. ShareBear prompts users only upon attempting to open a shared document for the first time. The prompt will not be displayed again once the users have accepted to open the file.
The expert successfully exploited this behavior by altering the file’s content and file extension after user agree to open it. ShareBear can download and update the file on the victim’s machine without any user interaction or notification. In short, the victim has given the attacker permission to plant a polymorphic file onto their machine and the permission to remotely launch it at any moment.
His research resulted in 4 zero-day bugs (CVE-2021-30861, CVE-2021-30975, and two without CVEs), 2 of which were used in the camera hack.
This is the second time Pickren has disclosed flaws in iOS and macOS that, if successfully exploited, could be abused to access the camera in an unauthorized manner upon visiting a specially crafted website.
















Comments