An Image was able to compromise Safari (2022 bug bounty)
In this video, we take a look into a universal cross site scripting (UXSS) attack on Safari within MacOS, allowing an attacker to gain access to all of your browser permissions, cookies, and execute arbitrary javascript within any websites context. Whether you're a pen tester, security researcher, or cyber security expert, having a solid foundation in web technologies, including JavaScript, sandboxing, and proper security practices are crucial. JOIN THE DISCORD! 👉 / discord Original bug report by Ryan Pickren: https://www.ryanpickren.com/safari-uxss MUSIC CREDITS: LEMMiNO - Cipher • LEMMiNO - Cipher (BGM) CC BY-SA 4.0 LEMMiNO - Firecracker • LEMMiNO - Firecracker (BGM) CC BY-SA 4.0 LEMMiNO - Nocturnal • LEMMiNO - Nocturnal (BGM) CC BY-SA 4.0 LEMMiNO - Siberian • LEMMiNO - Siberian (BGM) CC BY-SA 4.0 LEMMiNO - Encounters • LEMMiNO - Encounters (BGM) CC BY-SA 4.0 Music by Vincent Rubinetti Download the music on Bandcamp: https://vincerubinetti.bandcamp.com Stream the music on Spotify: https://open.spotify.com/artist/2SRhE... 0:00 – Intro 1:06 - Webarchive files 2:54 – Attack overview 4:15 – URI schemes & deep linking 5:59 - iCloud file sharing & ShareBear 10:06 - url files 11:28 - dmg files 12:40 - Full exploit chain 14:18 - Closing #programming #software #softwareengineering #computerscience #code #hacking #hack #cybersecurity #exploit #tracking #softwareengineer #vulnerability #pentesting #privacy #spyware #malware #cyber #cyberattack #zeroday #security #breaches #databreach #bug #bugbounty #penetrationtesting #backdoor #hacked #leak #exploitchain #zeroclick #chatbot #AI #chatgpt #openai #informationsecurity #trending #mac #apple #iphone #safari #xss #crosssitescripting #websecurity #browser #bowsersecurity #uxss #macOS #macvulnerability #insecure

The 'red flags' for AI giants at the heart of Elon Musk's 'big bet' IPO | Greg Williams

Say Goodbye to Passwords: Passkeys Explained Simply

Accidentally Formatted the Wrong Drive? Don't Panic Just Yet!

How Microsoft Accidentally Backdoored 270 MILLION Users

MAJOR EXPLOIT: GitLab was Hacked with an IMAGE??

Anthropic is starting to panic…

they tried to hack me so i confronted them

Unpatched "Design Flaw" in E2E encryption can track everything you do

How to Detect a Fake Cell Tower Spying on Your Phone (Stingray)

You go to google.com on a new computer. What happens next

What is a Proxy Server? | Networking Fundamentals Explained

The Most Mysterious File On The Internet

What is a Browser Security Sandbox?! (Learn to Hack Firefox)

I Built a Device That Freezes Wi-Fi Cameras | RF-Clown v2

I Hacked This Temu Router. What I Found Should Be Illegal.

The Entire Internet is Broken

Where People Go When They Want to Hack You

Most Devs Get API Authentication Wrong ?

WALLBLEED: Inside Chinas most Devastating Leak

