[CVE-2016-1764] If You Can't Break Crypto, Break the Client: Recovery of Plaintext iMessage Data
Summary
Technical write-up of CVE-2016-1764: a JavaScript URI plus the missing same-origin policy in OS X Messages' embedded WebKit let attackers exfiltrate entire iMessage histories with one click.
- Published
- Collected
Skip to content