this post was submitted on 23 Feb 2024
10 points (100.0% liked)

Cybersecurity

5984 readers
31 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

CVE-2024-23204 is a high-severity vulnerability (CVSS score of 7.5) in Apple's Shortcuts app, which could allow attackers to bypass the Transparency, Consent, and Control (TCC) framework on macOS and iOS devices. This framework is designed to protect user privacy by requiring explicit permission before accessing sensitive data. The vulnerability was exploited by using the 'Expand URL' function within Shortcuts to send base64-encoded data to a malicious server without user consent. Apple has addressed the issue with additional permission checks, and users are advised to update their devices to the latest versions and exercise caution when executing shortcuts from untrusted sources. Regular security updates from Apple should also be checked and applied.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here