Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-26766 PoC — Apple TV 4K和Apple TV HD 信任管理问题漏洞

Source
Associated Vulnerability
Title: Apple TV 4K和Apple TV HD 信任管理问题漏洞 (CVE-2022-26766)
Description:A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.
Description
Proof-of-concept for CVE-2022-26766 on macOS 12.3.1
Readme
Demo for Linus Henze's CoreTrust bug (CVE-2022-26766, CoreTrust allows any root certificate)

See https://worthdoingbadly.com/coretrust/ for usage.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →