Elektrine lite

← Feed

@wdormann@infosec.exchange

Post #4239983

2026-07-30 12:10 UTC

OK, despite the fact that Google is still unaware of the blog post, @vunix@infosec.exchange pointed out that the referenced blog post is here And confirms that the CVE is: CVE-2026-43760 An app may be able to access user-sensitive data And also mentions that not only does the vulnerability allow for reading of files as root, but also writing. How did Apple screw up the description so bad? No mention of a remote attacker? No mention of the ability to write a file as root, all by an unauthenticated remote attacker? The CVSS is buggered as well: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, which claims that the attack is LOCAL, and also has no effect on Availability or Integrity. (And thus a final score of 5.5) Maybe I'm being naive, but I get the impression that there's a lot that one can do with the ability for an unauthenticated remote attacker to be able to place files as root. 🤦‍♂️

Replies (0)

No replies.