Classicipods
No Result
View All Result
  • Home
  • Apple
    • Apple Laptops
    • Apple Music
    • Apple TV
    • Apple Watch
    • Airpods
  • Iphone
    • Best Iphone
    • Iphone 11
    • Jailbreak
    • Iphone Xr
  • Mac
    • Mac Book
    • Mac os
    • Mack Book Air
    • Sierra
  • Others
    • Itunes
    • Iclouds
  • Home
  • Apple
    • Apple Laptops
    • Apple Music
    • Apple TV
    • Apple Watch
    • Airpods
  • Iphone
    • Best Iphone
    • Iphone 11
    • Jailbreak
    • Iphone Xr
  • Mac
    • Mac Book
    • Mac os
    • Mack Book Air
    • Sierra
  • Others
    • Itunes
    • Iclouds
No Result
View All Result
Classicipods
No Result
View All Result
Home Iclouds

Apple pays $5,000 bug bounty for iCloud XSS bug discovery

by classicipod
February 22, 2021
in Iclouds
0
Apple pays $5,000 bug bounty for iCloud XSS bug discovery
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


A safety researcher from India was awarded $5,000 from Apple by way of its bug bounty program, after discovering a cross-site scripting (XSS) flaw in iCloud. Because the discovery of the difficulty, Apple has patched the difficulty in iCloud.com.

The vulnerability discovered by Vishal Bharad concerned making a file in Pages or Keynotes on the iCloud web site, a part of Apple’s iWork bundle. The file was created with a particular title that contained the specified XSS payload.

After sending the file to a different person or collaborating with them, the attacker then needed to make modifications to the doc and put it aside, the researcher suggested in a blog post. Altering “Browse All Variations” in Settings then triggers the operating of the XSS payload on the opposite person’s gadget.

The bug has been identified to Apple for fairly some time, with Bahrad disclosing it to the corporate on August 7, 2020. After reviewing the report and the steps to breed, in addition to a video demonstrating the bug, Apple awarded Bharad with $5,000 on October 9. Bharad publicly disclosed the flaw on February 14.

The researcher admitted that the bug was found as a part of a fishing journey to try to uncover at the least one subject with the iCloud web site. After failing to search out points in areas comparable to CSRF, IDOR, and enterprise logic bugs, Bharad then moved onto XSS bug-finding, a weak space for the researcher.

They then “inserted payloads in every single place” in a bid to search out methods to view and set off a payload that wasn’t beforehand found, which they finally managed to perform.

On Thursday, Apple revealed a detailed guide to safety mechanisms included in its software program and {hardware} merchandise. This included updates on security measures regarding the M1 chip, the iMessage sandboxing mechanism known as BlastDoor, and its bug bounty program.

Apple opened up its bug bounty program to all researchers in 2019 concurrently growing the charges of pay for disclosed bugs to a ceiling of $1 million in restricted circumstances. The profitable rewards have attracted many to begin taking up Apple’s safety.

One “Signal In with Apple” vulnerability disclosed in Might 2020 earned its discoverer $100,000, whereas a group of researchers spent three months hacking Apple and earned greater than $50,000 in October.

On February 10, it was revealed a safety researcher had hacked the internal systems of a number of main corporations, together with Apple, Microsoft, and PayPal. They earned greater than $130,000 in bug bounties, with Apple contributing $30,000.



Source link

ShareTweetPin

Related Posts

iCloud Photos to Google Photos: How to transfer directly
Iclouds

iCloud Photos to Google Photos: How to transfer directly

March 4, 2021
iCloud vs. Google Photos: Apple Now Allows Transferring Images to Third-Party Cloud Based App
Iclouds

iCloud vs. Google Photos: Apple Now Allows Transferring Images to Third-Party Cloud Based App

March 4, 2021
DoMarks is a new bookmarking app with a cool to-do twist
Iclouds

DoMarks is a new bookmarking app with a cool to-do twist

March 4, 2021
Beware of trade in via mail
Iclouds

Beware of trade in via mail

March 3, 2021
Apple now lets you automatically transfer your iCloud Photo Library to Google Photos
Iclouds

Apple now lets you automatically transfer your iCloud Photo Library to Google Photos

March 3, 2021
Apple confirms it does not hold your Apple ID hostage due to missed Apple Card payment
Iclouds

Apple confirms it does not hold your Apple ID hostage due to missed Apple Card payment

March 3, 2021
Next Post
The 101 Best Movie Endings of All Time, Ranked

The 101 Best Movie Endings of All Time, Ranked

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • 21.8M Fans
  • 81 Followers
  • 462 Subscribers
  • 284 Followers

Recommended

Australian singer Tones and I tops Apple Music list of most-streamed songs

Australian singer Tones and I tops Apple Music list of most-streamed songs

December 3, 2020
How to Erase an M1 Mac

How to Erase an M1 Mac

March 3, 2021
YG’s ‘F— Donald Trump’ Sees Huge Streaming Spike After Biden Victory

YG’s ‘F— Donald Trump’ Sees Huge Streaming Spike After Biden Victory

November 9, 2020
Dubai Design District launches curated playlists for local musicians on Apple Music – Campaign Middle East

Dubai Design District launches curated playlists for local musicians on Apple Music – Campaign Middle East

November 9, 2020
Woot has a boatload of iPhones and Apple Watches on sale at excellent prices today only

Woot has a boatload of iPhones and Apple Watches on sale at excellent prices today only

October 20, 2020
Arcata Police Log: In a world where consequences are only randomly applied, so much is possible

Arcata Police Log: In a world where consequences are only randomly applied, so much is possible

January 24, 2021
March 2021
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Feb    

Categories

  • Airpods
  • Apple Laptops
  • Apple Music
  • Apple TV
  • Apple Watch
  • Best Iphone
  • Iclouds
  • Iphone 11
  • Iphone Xr
  • Itunes
  • Jailbreak
  • Mac Book
  • Mac os
  • Mack Book Air
  • Sierra
iKON Rockets to No. 1 of iTunes Charts Around the World with New Song ‘Why Why Why’

iKON Rockets to No. 1 of iTunes Charts Around the World with New Song ‘Why Why Why’

March 4, 2021
Leaked Image Offers First Glimpse of Possible Apple Pencil 3

Leaked Image Offers First Glimpse of Possible Apple Pencil 3

March 4, 2021
iCloud Photos to Google Photos: How to transfer directly

iCloud Photos to Google Photos: How to transfer directly

March 4, 2021
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2020 Classicipod

No Result
View All Result
  • Home
  • Apple
    • Apple Laptops
    • Apple Music
    • Apple TV
    • Apple Watch
    • Airpods
  • Iphone
    • Best Iphone
    • Iphone 11
    • Jailbreak
    • Iphone Xr
  • Mac
    • Mac Book
    • Mac os
    • Mack Book Air
    • Sierra
  • Others
    • Itunes
    • Iclouds

© 2020 Classicipod

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?