18 ms·
Zero click vulnerability in Apple’s macOS Mail
- threatofrain 6y ago> 2020–05–16: Issue found > 2020–05–24: PoC done and reported to Apple > 2020–06–04: Catalina 10.15.6 Beta 4 with [hotfix released] > 2020–07–15: Catalina 10.15.6 Update with hotfix released
- lehi 6y ago> 2021–03–30: Bug Bounty is still being evaluated
- marshmallow_12 6y agoIf Apple are actually serious, why are they taking so long to give the bounty? It's sounds like madness to me.
- stephc_int13 6y agoThis is clearly what triggered the post. Work was done but not paid. Shitty business on Apple side...
- Hnrobert42 6y agoThose who fix the bug and those who issue payment are likely in two different groups with two different sets of motivators. Not excusing but explaining.
- MuffinFlavored 6y agoThe company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.
- adolph 6y agoA company sufficiently large enough for such an amount to not be a big deal will have a money disbursal process nobody understands enough to make a one time transaction of that size in a reasonable amount of time.
- cj 6y agoFinance can always be subverted by management, but it has to be a priority.
- eyelidlessness 6y agoMaybe a company so large it can’t track its own finances is too large to be responsible for its obligations and should be held to standards at least as strict as its less capable business and human peers. And I’m an Apple fan to be clear. But their wealth is the opposite of an excuse.
- fractionalhare 6y agoThat's not an excuse. It's just a blunt explanation. Out of the ordinary processes can only proceed so quickly in the presence of massive bureaucracy.
- adolph 6y agoIt isn’t that finances aren’t tracked. They are tracked and audited and the audits are audited and there are many safeguards in place so that money doesn’t leak out and the knowledge for that operation is specialized, so much so that entire departments handle only part of the process and can’t just talk to one another due to the “segregation of duties” the auditors want. A company that decided to incentivize bug bounty like Google got support for the program on high and all the wheels of the org went to work to create policy, procedure, forms, auditor review, SARBOX compliance, etc and payouts will move like any other invoice. A company where some mid rank sees a need for such a program but doesn’t get full organizational alignment will be stuck with a pre-broken unreliable process.
- _alex_ 6y agoThat's gonna be devastating to the three people who use Mail.app
- ratww 6y agoThat's not what the statistics say: https://emailclientmarketshare.com https://emailclientmarketshare.com
- wahern 6y agoWow, Mail.app has more market share than Outlook. I'm pleasantly surprised. Ditto for GMail only having ~30%. Although, > Since determining the client in which an email is opened requires images to be displayed, the data for some email clients and mobile devices might be over- or under-represented due to automatic image blocking. Outlook doesn't display external images by default, while Mail.app does, so....
- iamacyborg 6y agoAlso, I assume there's a different demographic that uses Mail vs Outlook. Those different demographics will receive different types of email, which may or may not be represented differently by companies who use Litmus tracking which is how this data is being collected.
- cozzyd 6y agoright, neither does Evolution or Thunderbird. It's crazy that Mail.app does this.
- uberduper 6y agoAs far as I know and recall from the years I've been using Mail.app, it does not download external images by default.
- wahern 6y agoIt does. I even provided a citation several weeks ago in another thread, though a quick Google search seems to bring up ample support of its own. Like me you may have disabled it and forgotten. Whenever I get a new laptop at work I tend to go through and change all the defaults, such as reverting to plaintext composition, and habitually disable external image loading as part of the process. The iPhone Mail app may have saner defaults, however, but I don't have an iPhone and have never used its e-mail client.
- Zhenya 6y agoIt seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.
- hbbio 6y agozerodium
- megablast 6y agoDoes it? It seems the priority should be fixing the issue.
- Zhenya 6y agoDo you think the finance department is pushing the changes?
- whimsicalism 6y agoPresumably not paying out has a chilling effect on bug identification by good guys.
- smoldesu 6y agoA considerably larger priority is identifying the issues before bad actors can take advantage of it.
- spitfire 6y agoBug bounty factoring! From wikipedia: > Factoring is a financial transaction and a type of debtor finance in which a business sells its accounts receivable (i.e., invoices) to a third party (called a factor) at a discount.[1][2][3] A business will sometimes factor its receivable assets to meet its present and immediate cash needs.[4][5] Forfaiting is a factoring arrangement used in international trade finance by exporters who wish to sell their receivables to a forfaiter.[6] Factoring is commonly referred to as accounts receivable factoring, invoice factoring, and sometimes accounts receivable financing. Accounts receivable financing is a term more accurately used to describe a form of asset based lending against accounts receivable. The Commercial Finance Association is the leading trade association of the asset-based lending and factoring industries.[7]
- swiley 6y agoIt's hardly surprising, you can run into memory corruption bugs just using desktop mail.app the way it's intended (there's been a bug that corrupts the account list for probably a decade which just hasn't been fixed.) Mutt may look old but at least it actually works.
- slimsag 6y agoImportant to note this isn't a memory corruption bug, though. This is a case of the application working as designed, but in unintended ways. A logic flaw. I say this because I don't see a lot of effort being put into solving these types of security issues, compared to e.g. memory safety issues.
- brundolf 6y agoUnlike memory safety issues it's not really a category that tends to have category-wide solutions
- eyelidlessness 6y agoV1: “This file we downloaded for your convenience is requesting access to [folder]. This may harm your computer or expose you to unknown security risk. Are you sure?” V2: “This file unexpectedly tried to access [folder].” The exact same mechanism Apple already used with GateKeeper and FS access for programs at runtime. Why does it need to be more complicated than that?
- saagarjha 6y agoYep, it’s a confused deputy problem.
- coder543 6y agoMutt has also had a number of remote code execution vulnerabilities over the years: https://www.cvedetails.com/product/274/Mutt-Mutt.html?vendor_id=158 https://www.cvedetails.com/product/274/Mutt-Mutt.html?vendor...
- tyingq 6y agoI thought macOS mail rules could also run a snippet of AppleScript. Wouldn't that make this an RCE? Or maybe the script has to exist in some folder this vulnerability doesn't have access to?
- turmio 6y agoThats what I thought first too (I am the author). And your guess for the reason is right. AppleScripts need to be stored in ~/Library/Application Scripts/com.apple.mail directory which is outside of the sandbox.
- hkdobrev 6y agoPlease don't use "zero" and "vulnerability" in the same sentence, unless you mean a zero-day one. The author could have said "no click vulnerability" with the same meaning. Almost caused me a concern with that title! :D :D
- turmio 6y agoSorry about that. But thats the term what is used by Apple to these type of bugs: https://developer.apple.com/security-bounty/ https://developer.apple.com/security-bounty/ ( Zero-click unauthorized access to sensitive data )
- petra 6y agoIs it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?
- tempfs 6y agoApple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.
- etaioinshrdlu 6y agoApple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.
- viraptor 6y agoI wouldn't call it extreme when there was a known public website allowing one-click jailbreak for good few months (not sure if it was actually ever patched or just the iOS version got eol)
- ghughes 6y ago10 years ago, yeah. https://en.m.wikipedia.org/wiki/JailbreakMe https://en.m.wikipedia.org/wiki/JailbreakMe
- Wowfunhappy 6y agoActually, Safari has been used for exploits much more recently than that! https://totally-not.spyware.lol/ https://totally-not.spyware.lol/ (iOS 10, 2018)
- _underfl0w_ 6y ago
- microtherion 6y agoThanks for an exceptionally clear writeup. Pay that person their bounty!
- turmio 6y agoThanks!
- igammarays 6y agoOk, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
- mhh__ 6y ago> 3-letter agency From the wikipedia page for Meltdown: "On 8 May 1995, a paper called "The Intel 80x86 Processor Architecture: Pitfalls for Secure Systems" published at the 1995 IEEE Symposium on Security and Privacy warned against a covert timing channel in the CPU cache and translation lookaside buffer (TLB). This analysis was performed under the auspices of the National Security Agency's Trusted Products Evaluation Program (TPEP)." i.e. did they know even in 1995?
- vmladenov 6y agoMy understanding is that people at the time were aware of potential problems but no vulnerability had been identified. I found some discussion here: https://security.stackexchange.com/a/177256 https://security.stackexchange.com/a/177256
- gumby 6y agoNSA used to have an active effort on information assurance, under the philosophy that it defended the country to have good civilian security (same reason for the NSA’s modification to the DES S-box). This unfortunately has fallen by the wayside. (NSA shortened the key as well so it wasn’t all bunnies and chocolate)
- gruez 6y agoIs this referencing the slow turnaround time, or the lack of a bounty paid so far? If it's the latter, I think it's already well known that bug bounties pay far less than the "market" value of such exploits.
- igammarays 6y ago> well known Well I didn't know, until now. I saw the bug bounty page at Apple before, was dazzled by the numbers, and didn't think twice about approaching them if I found a bug. Now after this article I know better than to trust them to pay.
- nvahalik 6y agoUse MailMate! https://freron.com/ https://freron.com/
- LVB 6y agoHow has maintenance & bug fixing been? I'm OK with mature apps stabilizing and needing few updates, though since it is a single dev with somewhat infrequent changes I thought I'd ask (https://updates.mailmate-app.com/release_notes https://updates.mailmate-app.com/release_notes).
- nvahalik 5y agoI’ve not noticed any issues. The author is very active on the mailing list.
- musicale 6y ago> Mail will parse it to find out any attachments with x-mac-auto-archive=yes header in place. Mail will uncompress those files automatically. What could possibly go wrong? ;-/
- techrat 6y agoThis is the same exact issue that used to plague Outlook back in the day with the automatic handling of attachments. You'd think Apple would have learned from others' mistakes.
- srswtf123 6y ago> You'd think Apple would have learned from others' mistakes. Why would you think that?
- woodruffw 6y agoI don't exactly have a dog in this, but I think this is a strange framing: this feels like exactly the kind of niche feature that was added by one engineer and then forgotten about. MS and Apple are both large companies that maintain individual pieces of software that are probably older than many of the engineers who currently work on them; the lessons here are more organizational than technical.
- techrat 6y agoIt's because Apple framed themselves as the company of "LOL Macs don't get viruses" and emphasize themselves to be more privacy focused than Android... ...and they made the same basic mistake of allowing one of the single most exploitable attack vectors ever. They kinda shoulda known better, honestly.
- eyelidlessness 6y agoThey still treat PDF files as “safe” to automatically open when downloaded so nope.
- 6y ago
- lupire 6y agoThat's a terrible unzip program. Unzip Programs should not write to arbitrary locations while unzipping.
- ummonk 6y agoNot only are symlinks a danger with unzipping libraries / utilities, but so are files with “..” in their path.
- asddubs 6y agogood old symlinks, always wreaking havoc
- fortran77 6y agoHow does Apple claim they're "secure by design?" [1] They seem to have the same issues as everyone else. [1] https://www.apple.com/business/docs/site/AAW_Platform_Security.pdf https://www.apple.com/business/docs/site/AAW_Platform_Securi...
- tyingq 6y agoIt's fairly clear most of their focus is on iOS and not macOS.
- skewlrules 6y agoThis is marketing.
- saagarjha 6y agoMore content for the linked list: https://news.ycombinator.com/item?id=24958256 https://news.ycombinator.com/item?id=24958256
- fortran77 6y agoThanks for taking the time to track this.
- viktorcode 6y agoThe claim is not "there's no exploitable bugs". Secure by design usually means that certain mechanisms are present in the system that mitigate security issues. Sandbox is one of them.
- rfd4sgmk8u 6y agoFor all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try to earn a dishonest living with pain and death in their wake. Are you using your skills to improve life on this rock, or are you trying to make it worse for a pay day?
- distribot 6y agoI agree with and appreciate your position. I'm more annoyed with Apple than with the security researchers. Apple is preying on your desire to do good. They could easily afford to pay a reasonable amount and promptly.
- whimsicalism 6y agoI don't see how selling to zerodium is more morally bankrupt than working for defense contractors, which plenty of tech people do.
- rfd4sgmk8u 6y agoThe output of the defense industry is used to hurt civilians less frequently. But I'm not here to excuse either.
- whimsicalism 6y ago> defense industry is used to hurt civilians less frequently ... based on?
- person_of_color 6y agoUm, how does that gel with thousands of engineers who work for FB?
- 6y ago
- oblib 6y agoSo, is this an issue on my old mac running 10.11.6 that will not get fixed?
- jhugo 6y ago10.11 is unsupported since September 2018. This is definitely not the only security issue you have.
- deleted 6y ago[deleted]
- Wowfunhappy 6y agoI'm on 10.9 and I don't want to use anything newer. I can deal with some risk, but this vulnerability is unacceptably bad. The core problem is that really dumb feature which auto-expands certain zip files. I need to turn that off. MailWebAttachment.h contains a method: - (BOOL)isAutoArchiveAttachment; I bet that if I Swizzle that to always return false, this "feature" will go away. I'll found out this weekend... Edit: Is the author's PoC available anywhere? Not that I really need it...
- Wowfunhappy 6y ago^ Yeah, that didn't work, the method never gets called. I'll have dig more...
- Wowfunhappy 6y agoGot it. Made very quickly but is working for me (which is all that really matters.) https://github.com/Wowfunhappy/Fix-Apple-Mail-CVE-2020-9922 https://github.com/Wowfunhappy/Fix-Apple-Mail-CVE-2020-9922 Had to make `-(BOOL)isAutoArchivePart` in `MCMimePart` return false.
- Hnrobert42 6y agoI’m curious and not attacking. Do you follow all security-related announcements for Mac OS and do your own back ports and fixes? How did you decide 10.9 is the right balance of risk for you?
- sitzkrieg 6y agohow stupid do you have to be to think automatically handling mail attachment compression in any way is a good idea
- KingMachiavelli 6y agoSounds like the sandbox still worked. Of course it's still bad but it show how sandboxing applications works well to contain exploits. Makes we wonder how many applications on Windows and MacOS actually support the system sandbox.
- turmio 6y agoThats true. Without sandbox this would have been much worse. Sandboxes are good speed bumps.
- cgufus 6y agoI can't find any information on the following questions: Are all past versions of OS X / Apple Mail affected? For what OS X Version does Apple provide a security update regarding this issue? Has anyone found a fix that prevents auto-uncompression (such as a "defaults write com.apple.mail xyz False" command)? Due to several reasons, I am also on an older Version of OS X and this issue makes me a bit nervous.
- tethys 6y agoFrom Apple's patch notes [0]: > Available for: macOS Mojave 10.14.6, macOS High Sierra 10.13.6, macOS Catalina 10.15.5 [0]: https://support.apple.com/en-us/HT211289 https://support.apple.com/en-us/HT211289
- deleted 6y ago[deleted]
- lgats 6y agohttps://cve.report/CVE-2020-9922 https://cve.report/CVE-2020-9922 https://support.apple.com/en-us/HT211289 https://support.apple.com/en-us/HT211289