Hackers could exploit this nasty Safari bug to lift files from your hard drive null


A bug in Apple’s Safari browser could be abused by hackers to leak or steal files from the devices of Mac and iOS users according to a new report from a security researcher.
Co-founder of the Polish security firm REDTEAM.PL, Pawel Wylecial first discovered the bug back in April and responsibly reported it to Apple. However, he decided to go public with his findings after the iPhone maker decided to delay patching the bug until the spring of 2021.
In his recently published blog post, Wylecial explains that the bug resides in Safari’s implementation of the Web Share API which is a new web standard that allows for cross-browser sharing of text, links, files and other content.
Apple’s browser allows users to share files that are stored locally on both their iOS or macOS devices. However, this feature could exploited by malicious web sites that secretly steal files from a user’s device when they try to share an article or other content online using Safari.
Safari Web Share API
Wylecial also included a proof-of-concept video in his blog post where he shows how the bug in the Web Share API can be used to steal a user’s /etc/passwd or browser history database files in Safari.
Although Wylecial has described the bug as “not very serious” due to the fact user interaction and complex social engineering are both required to trick users into leaking local files, he also pointed out that it would be quite easy for an attacker “to make the shared file invisible to the user”.
While the Web Share API bug is certainly concerning, so to is the way in which Apple handled Wylecial’s bug report. Typically security researchers give companies a 90-day vulnerability disclosure deadline before going public with their findings but by putting off patching the issue until the spring of next year, Apple forced Wylecial’s hand when it came to disclosing the vulnerability publicly.
As for the bug itself, Wylecial said that iOS versions 13.41 and 13.6 as well as macOS Mojave 10.14.16 with Safari 13.1 and macOS Catalina 10.15.5 with Safari 13.1.1 are all affected and there is currently no fix available for the issue.
Hopefully by publishing his findings publicly, Wylecial can convince Apple to expedite fixes for this bug and those disclosed by other security researchers.
Via ZDNet
A bug in Apple’s Safari browser could be abused by hackers to leak or steal files from the devices of Mac and iOS users according to a new report from a security researcher. Co-founder of the Polish security firm REDTEAM.PL, Pawel Wylecial first discovered the bug back in April and…
Recent Posts
- DOGE can keep accessing government data for now, judge rules
- In a test, 2000 people were shown deepfake content, and only two of them managed to get a perfect score
- Quordle hints and answers for Wednesday, February 19 (game #1122)
- Facebook is about to mass delete a lot of old live streams
- An obscure French startup just launched the cheapest true 5K monitor in the world right now and I can’t wait to test it
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010