Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2016-1764] If You Can't Break Crypto, Break the Client: Recovery of Plaintext iMessage Data

bishopfox.com | vulnerability | CVE-2016-1764 | #xss | #macos | #apple | #imessage | #cve-2016-1764

Summary

Technical write-up of CVE-2016-1764: a JavaScript URI plus the missing same-origin policy in OS X Messages' embedded WebKit let attackers exfiltrate entire iMessage histories with one click.
Published
Collected

original ↗

Related coverage

back