Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://www.zdnet.com/article/ios-mac-flaw-exposes-your-pass...

Where sending somebody a .tiff file via iMessage, web page, or email would give the attacker RCE on the device.



Unless I'm missing something this was patched before it was publicly announced.

I also don't think it had the impact you're suggesting, nor would it be as immediately palatable as a privacy issue to the layperson.


The article slug is misleading, and suggests a fundamental misunderstanding of the scope of the bug. A RCE in Messages does not allow attackers to steal your passwords.


The ask from the comment I’m responding to was for comparable vulnerabilities to this one, since this comment thread is discussing reputational damage from high-sev vulnerabilities. This vuln gives RCE in iMessage, which is an app that has microphone/camera access, so I’d say it’s clearly comparable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: