4 ms·
I’ve seen several projects like this that offer a network server with access to these Apple models. The danger is when they expose that, even on a loop port, to
by brians 6mo ago
I’ve seen several projects like this that offer a network server with access to these Apple models. The danger is when they expose that, even on a loop port, to every other application on your system, including the browser. Random webpages are now shipping with JavaScript that will post to that port. Same-origin restrictions will stop data flow back to the webpage, but that doesn’t stop them from issuing commands to make changes.
Some such projects use CORS to allow read back as well. I haven’t read Apfel’s code yet, but I’m registering the experiment before performing it.
- robotswantdata 6mo agoKeep seeing similar mistakes with vibe coded AI & MCP projects. Even experienced engineers seem oblivious to this attack vector
- stingraycharles 6mo agoI don’t think many browsers will allow posting to 127.0.0.1 from a random website. What’s the threat model here?
- brians 6mo agoI think any browser will allow it but not allow data read back.
- mememememememo 6mo agoIsn't there a CORS preflight check for this? In most cases. I guess you could fashion an OG form to post form fields. But openai is probably a JSON body only. The default scenario should be secure. If the local site sends permissive CORS headers bets may be off. I would need to check but https->http may be a blocker too even in that case. Unless the attack site is http.
- airza 6mo agoThere is a CORS preflight check for POST requests that don't use form-encoding. It would be somewhat surprising if these weren't using JSON (though it wouldn't be that surprising if they were parsing submitted JSON instead of actually checking the MIME-type which would probably be bad anwyay)
- btown 6mo agoFWIW this was the status quo (webpage could ping arbitrary ports but not read data, even with CORS protections) - but it is changing. This is partially in response to https://localmess.github.io/ https://localmess.github.io/ where Meta and Yandex pixel JS in websites would ping a localhost server run by their Android apps as a workaround to third-party cookie limits. Chrome 142 launched a permission dialog: https://developer.chrome.com/blog/local-network-access https://developer.chrome.com/blog/local-network-access Edge 140 followed suit: https://support.microsoft.com/en-us/topic/control-a-website-s-access-to-the-local-network-in-microsoft-edge-ef7eff4c-676d-4105-935c-2acbcd841d51 https://support.microsoft.com/en-us/topic/control-a-website-... And Firefox is in progress as well, though I couldn't find a clear announcement about rollout status: https://fosdem.org/2026/schedule/event/QCSKWL-firefox-local-network-access/ https://fosdem.org/2026/schedule/event/QCSKWL-firefox-local-... So things are getting better! But there was a scarily long time where a rogue JS script could try to blindly poke at localhost servers with crafty payloads, hoping to find a common vulnerability and gain RCE or trigger exfiltration of data via other channels. I wouldn't be surprised if this had been used in the wild.
- layer8 6mo agoRestricting such access it is still a work in progress: https://wicg.github.io/local-network-access/ https://wicg.github.io/local-network-access/
- brians 6mo agoThey offer it as an option but default it to false! This is still a --footgun option but it’s the least unsafe version I’ve seen yet! Well done, Apfel authors.
- franze 6mo agothx for the report - a totally valid attack vector i was not aware of before, should be fixed https://github.com/Arthur-Ficial/apfel/releases/tag/v0.6.23 https://github.com/Arthur-Ficial/apfel/releases/tag/v0.6.23 - see also new https://github.com/Arthur-Ficial/apfel/blob/main/docs/server-security.md https://github.com/Arthur-Ficial/apfel/blob/main/docs/server...
- snarkyturtle 6mo agoNoting that there's an option to require a Bearer token to the API