3 ms·
It's not clear from the tweet and video: How is his exfiltrator piggybacking on an excluded Apple process? Is nsurlsessiond in the exclude list?
by dexter0 6y ago
It's not clear from the tweet and video: How is his exfiltrator piggybacking on an excluded Apple process? Is nsurlsessiond in the exclude list?
- deleted 6y ago[deleted]
- _qulr 6y agoI don't think the video was intended to explain the technique. It's likely that Wardle is privately reporting the details to Apple Product Security.