3 ms·
> Also. There is nothing stopping someone for using this technique to publish an app in the AppStore officially. That's not accurate, the entitlements parsing
by objclxt 6y ago
> Also. There is nothing stopping someone for using this technique to publish an app in the AppStore officially.
That's not accurate, the entitlements parsing logic on the App Store submission system has always caught this, it's the client side parsing that doesn't.
You can't submit an app to the store that uses this exploit, because the store will reject it as having invalid entitlements.
- jannes 6y agoDo you know if TestFlight uses the same entitlements parsing logic? It may have been possible to exploit users' devices through beta versions.
- saagarjha 6y agoTestFlight apps are uploaded to App Store Connect as well.
- jackjeff 6y agoIndeed. I was wrong to assume Apple would not have yet another XML Parser somewhere else :) In that case it would only work with side loaded Apps signed with enterprise and developer certificates. I stand corrected. That being said I wonder... since we have two parsers on the device and one in submission process, if a more clever variant of this bug would have worked... I guess we will never know. For sure that parser is rock solid now.
- saagarjha 6y ago> For sure that parser is rock solid now. I wouldn’t be too sure.
- jiveturkey 6y agothatsthejoke.jpg