3 ms·
The author is right that controlling TextEdit seems harmless. It could be done in the context of showing the user release notes or something. AppleEvents must b
by peterbmarks 6y ago
The author is right that controlling TextEdit seems harmless. It could be done in the context of showing the user release notes or something.
AppleEvents must be a nightmare for Apple's security auditors.
- rgovostes 6y agoYou can tell another app to open a document without having permissions to send arbitrary Apple Events (which effectively let you act as a user interacting with the app). Even if TextEdit files were quarantined so you could not execute them, you would still be able to do harm, such as snooping on the user's recent documents, or trashing the disk by overwriting files that TextEdit has access to. Likely it could even install a LaunchAgent to run arbitrary code outside of the sandbox as well. There's already a security dialog here that warns the user. Maybe the user's imagination doesn't run wild with all the ways that the access could be abused, but they _were_ warned.