News Score: Score the News, Sort the News, Rewrite the Headlines

macOS Recovery Mode Safari allowed unrestricted writes to system partitions (and root persistence)

TL;DR: I accidentally discovered 2 vulnerabilities in macOS Recovery Mode's Safari: one allowing arbitrary writes to system partitions and root persistence (CVSS 8.5), the other allowing unrestricted file reads (CVSS 4.6). Technical write-ups HERE and HERE.It started like any other day with my M1 Macbook Air dying due to the hundreds if not thousands of Chrome tabs I had open, so I did what every normal human does and long pressed the touch id button to force a force restart (which I personally ...

Read more at yaseenghanem.com

© News Score  score the news, sort the news, rewrite the headlines