news.volyx.in

Zero-Click Calendar invite vulnerability chain in macOS (mikko-kenttala.medium.com)

461 points by jviide · 694 days ago · 159 comments on HN

Article summary

A zero-click vulnerability in macOS allowed attackers to send malicious calendar invites to victims, potentially stealing sensitive data without user interaction. The exploit chain had five steps and was reportedly fixed by Apple, but the researcher who discovered it has not yet received a bounty payment. The vulnerability was serious enough that it could have been sold to malicious actors for a significant amount of money. The researcher's experience highlights the challenges of working with companies to disclose and fix vulnerabilities.

Main themes

  • Zero-click vulnerabilities
  • macOS security
  • Bug bounty programs
  • Exploit chains
  • Responsible disclosure
  • Security researcher experiences

What commenters say

  • The bounty amount for this vulnerability should be substantial, potentially in the six-figure range, given its severity and the fact that it was a zero-click exploit.
  • Apple's bug bounty program is flawed because it often takes a long time to pay out, which can incentivize researchers to sell their findings to malicious actors instead.
  • The economics of bug bounties are different from those of the black market, and companies like Apple offer lower prices because they provide assured payouts and often require less exploit proof.
  • Lockdown Mode may prevent this type of vulnerability, but it is unclear whether it would have been effective in this specific case.
  • Some commenters believe that Apple's bounty program is sufficient and that the wait times are reasonable, while others think that the company should pay out more quickly and generously.
  • The vulnerability highlights the need for better security measures, such as whitelisting calendar invites, to prevent similar attacks in the future.
  • The fact that anyone can send calendar invites to any iCloud user without prior interaction or verification is a security risk that should be addressed.
  • The experience of the researcher who discovered this vulnerability is not unique, and many security researchers face similar challenges when working with companies to disclose and fix vulnerabilities.