Event JSON
{
"id": "b14eb45bc93ad6fa41045c499ce97a2acf63943a4d26f00cc238e37ee221cea0",
"pubkey": "bd211bf0d2b765604c065b021e3b34298f2136c0042cdb665b6bf6282b2689e3",
"created_at": 1784813050,
"kind": 1,
"tags": [
[
"proxy",
"https://mastodon.social/@mysk/116969508089535193",
"web"
],
[
"t",
"privacy"
],
[
"t",
"apple"
],
[
"t",
"macos"
],
[
"t",
"infosec"
],
[
"t",
"security"
],
[
"proxy",
"https://mastodon.social/users/mysk/statuses/116969508089535193",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://mastodon.social/users/mysk/statuses/116969508089535193",
"pink.momostr"
],
[
"-"
]
],
"content": "🚨 We're disclosing a macOS security bug that Apple says is not an issue.\nUsing a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.\nHere's a demo using Signal to steal its encryption key.\n📝 Blog with technical details: link in the replies.\nDo you think this should be considered a security bug?\n🎬👇\n#Apple #privacy #infosec #security #macOS\n\nhttps://youtu.be/0bOC8S3NQxI",
"sig": "7e190e419f5968df29df8980b10920d8cc1b171600ea13cb07fafe1923696acc8a334d8d51215b5db97f8f8303c3a9f9be1ad08684bab9ae5a750add5c710ae0"
}