Post #2723164
2026-05-19 14:55 UTC
📝🚨 New blog post: How a bug in Archive Utility allowed access to protected app data (including iMessage and WhatsApp chats, and Safari cookies) without any permissions.
The bug could also be exploited to hijack installed apps such as Signal and 1Password to perform phishing attacks.
Apple fixed the issue in macOS 26.4 as CVE-2026-28910, five months after we reported it
#Apple #macOS #privacy #security #cybersecurity #infosec
https://mysk.blog/2026/05/19/cve-2026-28910
Replies (2)
-
@mysk@mastodon.social 2026-05-19 14:55
macOS Archive Utility Bug Could Let Attackers Hijack Signal Sessions—Fixed in 26.4 (CVE-2026-28910) https://m.youtube.com/watch?v=WuH0pIE7j2Y
-
@softmaus@mastodon.social 2026-05-19 14:59
@mysk@mastodon.social Unfortunately, the main font‘s color seems to be white on white in Safari?