目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2022-22600 PoC — Apple tvOS 权限许可和访问控制问题漏洞

来源
关联漏洞
标题: Apple tvOS 权限许可和访问控制问题漏洞 (CVE-2022-22600)
Description:Apple tvOS是美国苹果(Apple)公司的一套智能电视操作系统。 Apple tvOS 存在权限许可和访问控制问题漏洞,该漏洞的存在是由于 Sandbox 中的权限逻辑不正确。恶意应用程序可以绕过某些隐私偏好。
Description
CVE-2022-22600 Proof of Concept
介绍
# MSF-screenrecord-on-MacOS
!!! This vulnerability has been simultaneously discovered or taken by Sudhakar Muthumani of Primefort Private Limited, Khiem Tran and listed as CVE-2022-22600. This is despite I already emailing Apple regarding this back in 2021.
## Affected Versions
As a student, I have limited access to devices in which I can test this vulnerability. The versions I have tested so far are `MacOS 12.1`, `MacOS 12.0`, and `MacOS 11.6.1`.

## POC
Files are in the POC directory. Just run `POC.sh` and a screenshot will be produced without TCC prompt.

## So what is the bug?
MacOS stores permissions based on executables. Thus, if the executable cannot be found after the code has already been loaded into memory, no permissions are restricted.
## Patched versions -- According to Apple
The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →