https://arstechnica.com/information-technology/2021/09/apple-airtags-can-be-abused-to-direct-finders-to-malicious-websites/
Apple forgot to sanitize the Phone Number field for lost AirTags Another bug-bounty boondoggle leads to public disclosure before the bug is fixed. Jim Salter - 9/30/2021, 6:16 PM Security consultant and penetration tester Bobby Rauch discovered that Apple's AirTags—tiny devices which can be affixed to frequently lost items like laptops, phones, or car keys—don't sanitize user input. This oversight opens the door for AirTags to be used in a drop attack. Instead of seeding a target's parking lot with USB drives loaded with malware, an attacker can drop a maliciously prepared AirTag. < - > According to reporting from Krebs on Security, Rauch is publicly disclosing the vulnerability largely due to communication failures from Apple—an increasingly common refrain. Rauch told Krebs that he initially disclosed the vulnerability privately to Apple on June 20, but for three months all the company would tell him is that it was "still investigating." This is an odd response for what appears to be an extremely simple bug to verify and mitigate. Last Thursday, Apple emailed Rauch to say the weakness would be addressed in a coming update, and it asked that he not talk about it publicly in the meantime. Apple never responded to basic questions Rauch asked, such as whether it had a timeline for fixing the bug, whether it planned to credit him for the report, and whether it would qualify for a bounty. The lack of communication from Cupertino prompted Rauch to go public on Medium, despite the fact that Apple requires researchers to keep quiet about their discoveries if they want credit and/or compensation for their work. Rauch expressed willingness to work with Apple but asked the company to "provide some details of when you plan on remediating this, and whether there would be any recognition or bug bounty payout." He also warned the company that he planned to publish in 90 days. Rauch says that Apple's response was "basically, we'd appreciate it if you didn't leak this." -- Iw mailing list [email protected] http://sticklist.org/mailman/listinfo/iw_sticklist.org
