3 ms·
You’re missing the point: - AppStore or not, you should not be able to access this file in an app. The exploit (plist parsing bug) is about breaking out of the
by jackjeff 6y ago
You’re missing the point:
- AppStore or not, you should not be able to access this file in an app. The exploit (plist parsing bug) is about breaking out of the sandbox and getting the permission to access system files (and much more!).
- Also. There is nothing stopping someone for using this technique to publish an app in the AppStore officially.
Or maybe I should have said “was”. Best case scenario Apple would retroactively check for naughty plist files in Apps submitted to the AppStore present and past, and ban developers that used the same hack. That being said, this is reactive and the damage would already be done.
This hack is not using a private API or doing something that Apple would have caught during App review. Even the system file path could be obfuscated (or downloaded from Internet later on).
So “don’t install apps outside the App Store” did not really help in this case.
- objclxt 6y ago> Also. There is nothing stopping someone for using this technique to publish an app in the AppStore officially. That's not accurate, the entitlements parsing logic on the App Store submission system has always caught this, it's the client side parsing that doesn't. You can't submit an app to the store that uses this exploit, because the store will reject it as having invalid entitlements.
- jannes 6y agoDo you know if TestFlight uses the same entitlements parsing logic? It may have been possible to exploit users' devices through beta versions.
- saagarjha 6y agoTestFlight apps are uploaded to App Store Connect as well.
- jackjeff 6y agoIndeed. I was wrong to assume Apple would not have yet another XML Parser somewhere else :) In that case it would only work with side loaded Apps signed with enterprise and developer certificates. I stand corrected. That being said I wonder... since we have two parsers on the device and one in submission process, if a more clever variant of this bug would have worked... I guess we will never know. For sure that parser is rock solid now.
- saagarjha 6y ago> For sure that parser is rock solid now. I wouldn’t be too sure.
- jiveturkey 6y agothatsthejoke.jpg
- willstrafach 6y ago> There is nothing stopping someone for using this technique to publish an app in the AppStore officially. It has not happened though. Only app which has been in the App Store and utilized private entitlements, from what I’ve seen anyway, has been Uber.