Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Since iOS 18 launched, the new Passwords app has been using unencrypted HTTP to download icons for password entries—a potential #security risk. We reported this bug to #Apple in September, and it’s finally fixed in #iOS 18.2 (CVE-2024-54492). Why does this matter? Watch 🎬 :

156,542 Aufrufe • vor 1 Jahr •via X (Twitter)

10 Kommentare

Profilbild von Mysk 🇨🇦🇩🇪
Mysk 🇨🇦🇩🇪vor 1 Jahr

The CVE is classified as CRITICAL by @TenableSecurity. Make sure you upgrade your devices (Mac, iPhone, iPad). Here's the same video uploaded to YouTube (Subscribe to the channel too😊):

Profilbild von Mysk 🇨🇦🇩🇪
Mysk 🇨🇦🇩🇪vor 1 Jahr

More details:

Profilbild von Léo
Léovor 1 Jahr

Congrats for this finding! Releasing an app using http in 2024 sound like a joke 🤦‍♂️

Profilbild von Mysk 🇨🇦🇩🇪
Mysk 🇨🇦🇩🇪vor 1 Jahr

Thank you 🙏

Profilbild von Chris Marstaller
Chris Marstallervor 1 Jahr

What security risk? Yes, it should be over https, but what’s the actual risk? The issue is privacy, maybe? But maybe I’m missing what the *security* risk is? Assuming the icon is parsed properly and doesn’t somehow run arbitrary remote code… But even on the privacy angle, what’s the leaking of privacy. The website already knows you are a user? Wouldn’t it be *better* for Apple to write a secure proxy to get (and cache) icons or use its own “Apple Business Connect” database?

Profilbild von nakadachi
nakadachivor 1 Jahr

This is mindblowing. Great catch and really bad move from Apple

Profilbild von Matt
Mattvor 1 Jahr

This is inspiring! It doesn't matter how terrible of a developer you are, there's a job for you at Apple 🥰

Profilbild von andyH
andyHvor 1 Jahr

Thanks for all your work in security, it helps maintain a reliable system. Hope you got a reward.

Profilbild von Mysk 🇨🇦🇩🇪
Mysk 🇨🇦🇩🇪vor 1 Jahr

Thank you 🙏 The bounty reward is still "in review"

Profilbild von emn
emnvor 1 Jahr

tbh, it's crazy that a 3.7 trillion dollar company hasn't noticed this itself.

Ähnliche Videos