正在加载视频...

视频加载失败

There is a vulnerability in LSApplicationWorkspace… seems like there is possibility for a DenialOfService attack… why… it’s open selector that is handled by an other process fails to check if its caller is still alive. It’s immune to App switcher kills, uninstall, etc…

21,159 次观看 • 1 年前 •via X (Twitter)

8 条评论

SeanIsTethered 的头像
SeanIsTethered1 年前

Aka.. there is no time to even invoke the menu where the uninstall button is located, if there is an auto launch vulnerability in combination… this can brick ur phone

SamoXcZ ☁︎ 的头像
SamoXcZ ☁︎1 年前

U should’ve reported it to apple bug bounty lol

SeanIsTethered 的头像
SeanIsTethered1 年前

I did. It would be my CVE anyways dw… I don’t want bounty!

Văn Lợi Nguyễn 的头像
Văn Lợi Nguyễn1 年前

Cool

Appl Bll 的头像
Appl Bll1 年前

you have that many apps through dev cert?

SeanIsTethered 的头像
SeanIsTethered1 年前

Dev cert is unlimited apps

Tikimanup 的头像
Tikimanup1 年前

How the f this happened This is scary

SeanIsTethered 的头像
SeanIsTethered1 年前

Yep, especially because this selector is used by many sideloading apps and 3rd party AppStore. This vulnerability exists likely since Launch Services exists and was uncaught… I assume it works from iOS 2.0 to iOS 18.4.1

相关视频