
As discovered by a security researcher, a malicious actor can hack an iOS or macOS camera with a single click on a link, exploiting zero-day in Safari.
iOS and macOS security requires any app that wants to access the camera to manually ask for permission. However, Apple apps like Safari have access by default.
Security researcher Ryan Pickren has discovered seven new vulnerabilities in the Safari browser, which allow an attacker to access a device's camera, microphone, or location , and in some cases, even access saved passwords.
Exploiting bugs to access the camera
The security researcher began exploiting the bugs using JavaScript data parameters and while he was initially unsuccessful, when he tried to parse through the file path used for remote or FTP access (file://host.example.com/Share/path/to/file.txt), Safari treated it as a regular URL.
“The page accepted this URL and reloaded the same content, meaning I was able to change the document.domain using this simple trick.”
So now the Safari browser thinks the linked website is skype9.0com. By opening the local file, attackers can run a malicious script and gain access to the camera, microphone, and screen sharing .
He also discovered another bug (CVE-2020-9784 & CVE-2020-3887) that bypasses automatic download prevention in the Safari browser.
Using the URI blob://skype.com a popup can be triggered and used to execute arbitrary JavaScript.
Using all of these vulnerabilities one can gain access to iOS/macOS camera, microphone or location and in some cases, saved passwords.
