
Mysk 🇨🇦🇩🇪
@mysk_co • 20,653 subscribers
We're two #iOS developers and occasional #security researchers on two continents. #CyberSecurity 📝https://t.co/69k7WAphKl 🇨🇦🇩🇪 Current Project: @psylo_app
Shorts
Videos

😱 iOS 26.4.2 still leaks the real IP when updating VPN apps. Motivated by Mullvad's recent blog, we made a website that logs the iPhone IP every second. We started Mullvad VPN, opened the website, then let Mullvad updated in the background. See the leaks in action.. 🤯
Mysk 🇨🇦🇩🇪728,128 Aufrufe • vor 2 Monaten

🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇 This happens entirely in the background, with no password prompts or visible alerts. The modified binaries can then access the original app's keychain records and protected containers. We reported this to Apple two weeks ago and haven't received a response. We previously said we wouldn't contact Apple's bounty program again, but we believe it's necessary in this case to help protect Mac users. It affects macOS 26 and 27. This bug doesn't impact apps downloaded from the Mac App Store. Many developers distribute apps on the web instead because Apple controls the App Store's review process and payment methods.
Mysk 🇨🇦🇩🇪95,456 Aufrufe • vor 24 Tagen

😎🔬 Proton VPN just got updated. When iOS updated the app with the kill switch on, it was a total mess: iOS blocked internet for nearly 6 minutes, then terminated the app and its VPN tunnel, exposing iPhone traffic and IP. The VPN required a manual restart 😠. Watch this demo:
Mysk 🇨🇦🇩🇪178,413 Aufrufe • vor 2 Monaten

Signal Desktop is not secure. With every vulnerability we discover on macOS, we find Signal Desktop to be an easy target. In this video, we show how a Signal session can be stolen and restored on a remote Mac without the user being aware. Only use Signal on iPhone or Android
Mysk 🇨🇦🇩🇪36,948 Aufrufe • vor 2 Monaten

Since iOS 18 launched, the new Passwords app has been using unencrypted HTTP to download icons for password entries—a potential #security risk. We reported this bug to #Apple in September, and it’s finally fixed in #iOS 18.2 (CVE-2024-54492). Why does this matter? Watch 🎬 :
Mysk 🇨🇦🇩🇪156,358 Aufrufe • vor 1 Jahr

Found another example: iTunes Store Zero Liquid Glass and untouched since the iOS 7 flattening, but still you can get the latest Taylor Swift album The best part: the app still lets you customise the bottom tab bar, a feature that existed when iOS was still called iPhone OS
Mysk 🇨🇦🇩🇪80,667 Aufrufe • vor 9 Monaten

This is how you choose a default browser in iOS 17.4 in the EU. The prompt shows a list of browser options. Tapping on a browser option opens the browser's page on the App Store. What happens if any of these browsers is only available on an alternative marketplace?
Mysk 🇨🇦🇩🇪13,023 Aufrufe • vor 2 Jahren
Keine weiteren Inhalte verfügbar