macOS

Security researcher wh1te4ever shares Safari-based remote execution exploit patched in iOS 16.5.1, macOS 13.4.1

MacBook Pro Matrix Hack banner image.

In case you weren’t already aware, there was a Safari-based remote code execution (RCE) bug in the wild that Apple patched in a rapid security update for iOS & iPadOS 16.5.1 dubbed CVE-2023-37450, and ENKI WhiteHat is credited with the original proof of concept (PoC) showcasing the bug. But what if we told you someone made an exploit out of it? Interestingly enough, that seems to be exactly what has happened.

PoC published for CVE-2024-54498 macOS sandbox escape patched in macOS Sequoia 15.2

MacBook Pro Matrix Hack banner image.

Apple device security nerds, unless they’ve been living under a rock, have probably heard about CVE-2024-54498, or perhaps better known as the sharedfilelistd vulnerability. It was one of several vulnerabilities that Apple claims to have patched in macOS Sequoia 15.2, macOS Sonoma 14.7.2, and macOS Ventura 13.7.2, citing details shared on Apple’s About the security content of macOS Sequoia 15.2 web page.