Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page.
This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps.
PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance...
Breakdown and POC. 🧵
XSS to full account takeover and wallet drain in Ditto.
V12 found a deeplink parser bug that steals Nostr private keys with just one click.
Here's how. 🧵
Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud.
V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything.
Two separate critical bugs: arbitrary read and RCE.
Here's how. 🧵