HomeSecurityXSS flaw discovered in Apple iCloud domain

XSS flaw discovered in Apple iCloud domain

A cross-site scripting (XSS) vulnerability in the iCloud domain has reportedly been patched by Apple. Bug hunter and penetration tester Vishal Bharad claims to have discovered the security flaw, which is a stored XSS issue on icloud.com.

Stored XSS vulnerabilities, also known as “persistent XSS,” can be used to store payloads on a targeted server, inject malicious scripts into websites, and potentially be used to steal cookies, session tokens, and browser data.

According to Bharad, the XSS flaw on icloud.com was discovered in the Page/Keynotes functions of Apple's iCloud domain.

Apple iCloud

To trigger the bug, an attacker needed to create new Pages or Keynote content with an XSS payload submitted in the name field.

This content would then need to be saved and sent or shared to another user. An attacker would then need to make one or two changes to the malicious content , save it again, and then visit “Settings” and “Browser All Versions.”

After clicking this option, the XSS payload will be activated, the researcher said.

Bharad also provided a Proof-of-Concept (PoC) video to demonstrate the vulnerability.

The researcher disclosed the bug to Apple on August 7, 2020. The report was accepted and Bharad received a $5000 financial reward on October 9.

Bug bounty programs, such as those offered by HackerOne and Bugcrowd, remain very popular with external researchers looking to report security issues to technology vendors. In 2020 alone, Google gave bug bounty hunters $6.7 million for their reports.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS