macOS Security Bugs Exposed Safari History and Device Location to Unauthorized Apps
Read OriginalThis technical article details the discovery of macOS security vulnerabilities (CVE-2023-23506 and CVE-2023-28192) where improper client validation in XPC services allowed unauthorized applications to access sensitive data like Safari browsing history and device location. It explains the underlying cause—broken assumptions about the isolation of local XPC services—and provides a technical breakdown of XPC service types and their security implications.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser