3 ms·
Is it me or does "webcam hacking" really undersell the bug here? From the write up at https://www.ryanpickren.com/webcam-hacking https://www.ryanpickren.com/we
by 7777fps 7y ago
Is it me or does "webcam hacking" really undersell the bug here?
From the write up at https://www.ryanpickren.com/webcam-hacking https://www.ryanpickren.com/webcam-hacking , the bug chain appears to allow script execution in "arbitrary" domain context, which at first glance seems much bigger than just webcam extraction. Sticking up someone's face is attention grabbing compared to what could be done with that kind of power.
Is it because of the first bug in the chain that only the media-permissions was affected by the context confusion?
For example being able to extract cookies or local storage from other contexts would be a much bigger deal (local storage is sometimes used to store XSRF protection keys or other credentials), so I assume that wasn't at all affected?
Did any other parts of safari use the same broken context awareness as the media permissions or do we know that it was it isolated to media permissions?
- dannyw 7y agoThere’s only one way to find out: downgrade your Safari and call document.cookie using the PoC codes.
- 7777fps 7y agoI don't have any Mac devices or emulators or I would give it a try.
- lilyball 7y agoThis appears to only control the media permissions. I'm reading through the long writeup now and it talks about how this is something other than the site origin, instead it's running its own URL parser with custom logic against all pages in order to map them to website permissions.