Skip to main content

iOS/macOS Webcam Can be Hacked With A Single Click On Malformed Link – Hacker Rewarded $75,000

iOS/macOS Camera


By just making the users visiting a link, an attacker can hack the users’ iOS/macOS Camera using zero-day bugs in Safari.
With iOS and macOS camera security model every app needs to assigned permission manually but Apple’s own app such as Safari gets access by default.
Security researcher Ryan Pickren discovered seven new vulnerabilities with Safari browser that allows attackers to access your device’s camera, microphone, or location, and in some cases, saved passwords as well.
iOS/macOS Webcam
Pickren said that Safari not using the method of the origin to keep track of the open website, “I deduced that Safari was likely running a Generic URI Syntax parser against all open windows to get the URIs’ hostnames, then doing some extra parsing on those.”

Exploiting Bugs to Access Camera

He started exploiting using javascript: data: and about, but that fails, but while parsing file: which specified for remote or FTP purpose(file://host.example.com/Share/path/to/file.txt).
iOS/macOS Webcam
Safari parses it as a normal file URI, “the page actually accepted this URI as valid and reloaded the same content. Which means I just changed the document.domain using this really dumb trick. (CVE-2020-3885).”
So now the Safari browser thinks the website connected is skype9.0com, by opening the local file attackers can run a malicious script and gain access to Camera, Microphone, and Screen Sharing.
He found another bug (CVE-2020-9784 & CVE-2020-3887) to bypass the auto-download prevention in the Safari browser.
By using blob://skype.com URI a popup can be triggered and can be used to execute the arbitrary JavaScript.
Trying all chain of bugs can grant access to iOS/macOS camera, microphone, or location, and in some cases, saved passwords.
Following are the seven bugs
CVE-2020-3852 – A logic issue was addressed with improved validation.
CVE-2020-3864 – A DOM object context may not have had a unique security origin
CVE-2020-3865 – A top-level DOM object context may have incorrectly been considered secure
CVE-2020-3885 – File URL processed incorrectly.
CVE-2020-3887 – A download’s origin may be incorrectly associated
CVE-2020-9784 – Malicious iframe use another website’s download settings
CVE-2020-9787 – Hostnames with a dash (-) and period (.) are ignored
iOS/macOS Webcam
All the vulnerabilities patched in January and March updates. The researcher receives $75,000 for the bug submission.
Source : GBHackers

Comments

Popular posts from this blog

10 Best Forum Software For Webmasters

10 Best Forum Software For Webmasters Do you want to create your online discussion forum or online community where people can discuss about their favorite topics? In this article, you can see 10 best forum software (scripts for setting up discussion forums) that can be used free of cost. Although some scripts are paid but rest of these forum scripts are free to use.You only need to buy hosting space and domain name for your website and after then you can install any of these forum scripts to start your own discussion forums on the internet. Online discussion forums generate huge page views because thousands of people want to join online discussion forums to ask questions or share knowledge. Some of online marketers join forums to discuss about their products with community members. You don't need to acquire any kind of technical skill to run a professional discussion forums because these days, almost all web hosting providers offer one click script installer which h...

|Bypass Symlink on 2013 Server With Different .htaccess and Methods by Sen Haxor |

Hi, Guys,  Please a wonderfull tutorial provided bt Sem;\  Today I gonna Explain how to bypass Symlink on 2013 Server With Different .htaccess and Methods. So let's Get Started :) Note: This method is not applicable for Godaddy, Bluehost, Hostgator and Hostmonstor Servers. For This First You Need the Following Files : 1 -> Sen Haxor CGI Shell 2 -> sen.zip 3 -> passwd-bypass.php 4 -> Turbo Brute force Cpanel 5 - > Port.py First Before Starting to symlink we need to create php.ini and ini.php to Disable Safe mode and Disabled Functions on the server . Use the Following Code : Make a php.ini with the following code safe_mode=Off And ini.php with <? echo ini_get("safe_mode"); echo ini_get("open_basedir"); include($_GET["file"]); ini_restore("safe_mode"); ini_restore("open_basedir"); echo ini_get("safe_mode"); echo...

How to Hack WhatsApp using just a GIF

A picture is worth a thousand words, but a GIF is worth a thousand pictures. Today, the short looping clips, GIFs are everywhere—on your social media, on your message boards, on your chats, helping users perfectly express their emotions, making people laugh, and reliving a highlight. But what if an innocent-looking GIF greeting with Good morning, Happy Birthday, or Merry Christmas message hacks your smartphone? Well, not a theoretical idea anymore. WhatsApp has recently patched a critical security vulnerability in its app for Android, which remained unpatched for at least 3 months after being discovered, and if exploited, could have allowed remote hackers to compromise Android devices and potentially steal files and chat messages. WhatsApp Remote Code Execution Vulnerability The vulnerability, tracked as  CVE-2019-11932 , is a double-free memory corruption bug that doesn't actually reside in the WhatsApp code itself, but in an open-source GIF image parsing library that What...