Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
10 résultats taggé Safari  ✕
Safari Flaw Can Expose iPhone Users in the EU to Tracking https://www.mysk.blog/2024/04/28/safari-tracking/
09/05/2024 13:38:14
QRCode
archive.org

Apple's implementation of installing marketplace apps from Safari is heavily flawed and can allow a malicious marketplace to track users across websites

mysk EN 2024 ios macos safari Flaw iPhone EU Tracking
Chrome Users Now Worth 30% Less Money Thanks to Google's Cookie Killing, Ad Firm Says https://gizmodo.com/google-chrome-users-worth-less-money-cooking-killing-1851159736
15/01/2024 11:28:34
QRCode
archive.org
thumbnail

A week into phase one of Google’s cookie killing project in Chrome, early tests show how it could hit the web’s bottom line.

gizmodo EN 2024 Google Business Finance Online-advertising G/O-Media Tracking Jason-Kint Technology Internet Paul-Bannister Targeted-advertising Walmart Google-Chrome World-Wide-Web Privacy-Sandbox Safari Web-browsers disney META HTTP-cookie Internet-privacy Alphabet-Inc
iLeakage https://ileakage.com/
25/10/2023 23:45:04
QRCode
archive.org

We present iLeakage, a transient execution side channel targeting the Safari web browser present on Macs, iPads and iPhones. iLeakage shows that the Spectre attack is still relevant and exploitable, even after nearly 6 years of effort to mitigate it since its discovery. We show how an attacker can induce Safari to render an arbitrary webpage, subsequently recovering sensitive information present within it using speculative execution. In particular, we demonstrate how Safari allows a malicious webpage to recover secrets from popular high-value targets, such as Gmail inbox content. Finally, we demonstrate the recovery of passwords, in case these are autofilled by credential managers.

ileakage EN 2023 macos Safari Side-Channel ios Spectre speculative
Project Zero: An Autopsy on a Zombie In-the-Wild 0-day https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html
21/06/2022 08:57:54
QRCode
archive.org

Whenever there’s a new in-the-wild 0-day disclosed, I’m very interested in understanding the root cause of the bug. This allows us to then understand if it was fully fixed, look for variants, and brainstorm new mitigations. This blog is the story of a “zombie” Safari 0-day and how it came back from the dead to be disclosed as exploited in-the-wild in 2022. CVE-2022-22620 was initially fixed in 2013, reintroduced in 2016, and then disclosed as exploited in-the-wild in 2022. If you’re interested in the full root cause analysis for CVE-2022-22620, we’ve published it here.

googleprojectzero EN 2022 0-day Safari CVE-2022-22620 Apple
Jamf Threat Labs identifies Safari vulnerability (CVE-2022-22616) allowing for Gatekeeper bypass https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/
28/04/2022 10:52:08
QRCode
archive.org
thumbnail

The identified vulnerability allows bypassing of Gatekeeper security and app notorization, has been patched by Apple.

jamf 2022 EN Safari CVE-2022-22616 Gatekeeper Apple macOS
Safari Flaws Exposed Webcams, Online Accounts, and More https://www.wired.com/story/safari-flaws-webcam-online-accounts-mic/
15/02/2022 10:39:40
QRCode
archive.org
thumbnail

Apple awarded a $100,500 bug bounty to the researcher who discovered the latest major vulnerability in its browser.

apple safari vulnerabilities bugbounty WIRED webcam
Webcam Hacking (again) - Safari UXSS https://www.ryanpickren.com/safari-uxss
15/02/2022 10:38:37
QRCode
archive.org
thumbnail

$100,500 Apple Bug Bounty for hacking the webcam via a Safari Universal Cross-Site Scripting (UXSS) bug. CVE-2021-30861, CVE-2021-30975

GeorgiaTechHacker Pickren Safari UXSS Apple bugbounty CVE-2021-30861 CVE-2021-30975
Mettez à jour iOS ! WebKit contient une vulnérabilité dangereuse https://www.kaspersky.fr/blog/webkit-vulnerability-cve-2022-22620/18550/
11/02/2022 18:30:02
QRCode
archive.org
thumbnail

Apple a publié iOS 15.3.1 pour corriger la vulnérabilité CVE-2022-22620 de WebKit, qui serait activement exploitée par les cybercriminels.

version EN

CVE-2022-22620 Apple iOS iPadOS WebKit Safari FR Kaspersky
Nouvelle version de Safari 15.3 sur Big Sur et Catalina pour combler une faille importante | MacGeneration https://www.macg.co/logiciels/2022/02/nouvelle-version-de-safari-153-sur-big-sur-et-catalina-pour-combler-une-faille-importante-127163
11/02/2022 18:25:31
QRCode
archive.org
thumbnail

"Sorti hier, macOS 12.2.1 règle un problème de sécurité dans WebKit, le moteur de Safari, qui aurait pu permettre à une personne malintentionnée d'exécuter du code arbitraire en faisant simplement visiter à l'utilisateur une page web malveillante (CVE-2022-22620). Si votre Mac n'est pas compatible avec macOS Monterey, une mise à jour individuelle de Safari est disponible."

CVE-2022-22620 Safari BigSur Catalina FR
Apple Releases iOS, iPadOS, macOS Updates to Patch Actively Exploited Zero-Day Flaw https://thehackernews.com/2022/02/apple-releases-ios-ipados-macos-updates.html
11/02/2022 18:17:35
QRCode
archive.org

"Apple on Thursday released security updates for iOS, iPadOS, macOS, and Safari to address a new WebKit flaw that it said may have been actively exploited in the wild, making it the company's third zero-day patch since the start of the year."

CVE-2022-22620 iPadOs iOS macOS Safari EN
4252 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio