https://arstechnica.com/information-technology/2021/09/apple-airtags-can-be-abused-to-direct-finders-to-malicious-websites/

Apple forgot to sanitize the Phone Number field for lost AirTags
Another bug-bounty boondoggle leads to public disclosure before the bug is 
fixed.

Jim Salter - 9/30/2021, 6:16 PM

Security consultant and penetration tester Bobby Rauch discovered that Apple's 
AirTags—tiny devices which can be affixed to frequently lost items like 
laptops, phones, or car keys—don't sanitize user input. This oversight opens 
the door for AirTags to be used in a drop attack. Instead of seeding a target's 
parking lot with USB drives loaded with malware, an attacker can drop a 
maliciously prepared AirTag.

< - >

According to reporting from Krebs on Security, Rauch is publicly disclosing the 
vulnerability largely due to communication failures from Apple—an increasingly 
common refrain.

Rauch told Krebs that he initially disclosed the vulnerability privately to 
Apple on June 20, but for three months all the company would tell him is that 
it was "still investigating." This is an odd response for what appears to be an 
extremely simple bug to verify and mitigate. Last Thursday, Apple emailed Rauch 
to say the weakness would be addressed in a coming update, and it asked that he 
not talk about it publicly in the meantime.

Apple never responded to basic questions Rauch asked, such as whether it had a 
timeline for fixing the bug, whether it planned to credit him for the report, 
and whether it would qualify for a bounty. The lack of communication from 
Cupertino prompted Rauch to go public on Medium, despite the fact that Apple 
requires researchers to keep quiet about their discoveries if they want credit 
and/or compensation for their work.

Rauch expressed willingness to work with Apple but asked the company to 
"provide some details of when you plan on remediating this, and whether there 
would be any recognition or bug bounty payout." He also warned the company that 
he planned to publish in 90 days. Rauch says that Apple's response was 
"basically, we'd appreciate it if you didn't leak this."

-- 
Iw mailing list
[email protected]
http://sticklist.org/mailman/listinfo/iw_sticklist.org

Reply via email to