ios

11 articles
sort: new top best
clear filter
0 2/10

A tutorial on using Frida to intercept HTTPS traffic from Flutter iOS applications without requiring VPN or iptables configuration, likely focusing on SSL pinning bypass techniques.

Frida Flutter
pritessh.medium.com · Pritesh Mistry · 2 hours ago · details
0 2/10

Ghost Reader AI is an offline iOS app that performs on-device text-to-speech using the Kokoro-82M model, requiring no internet connection or cloud processing while maintaining complete user privacy and supporting multiple document formats (PDF, EPUB, web articles, Markdown).

Ghost Reader AI Kokoro-82M Jan Ancajas iPhone 15 Pro ElevenLabs Speechify Natural Reader
apps.apple.com · jantheman · 15 hours ago · details · hn
0 5/10

Researcher discovered a biometric authentication bypass in WhatsApp on both Android and iOS by exploiting the chat transfer feature when switching to WhatsApp Business, allowing unauthenticated access to locked chats. Two separate $500 bounties were awarded for Android (July 2023) and iOS (January 2024) variants of the same vulnerability.

WhatsApp WhatsApp Business Meta Facebook Himanshu Bharti Arvind
medium.com · Himanshu Bharti · 20 hours ago · details
0 7/10
vulnerability

AirDoS is a denial-of-service vulnerability in iOS that allows attackers to remotely spam nearby iPhones/iPads with infinite AirDrop share popups, rendering the UI unusable until the device is restarted or the user escapes Bluetooth/WiFi range. Apple patched it in iOS 13.3 (December 2019) with a rate limit that auto-declines requests after 3 rejections from the same device.

AirDoS iOS 13.3 macOS Catalina 10.15.2 opendrop Milan Stute Alexander Heinrich Apple
kishanbagaria.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 2/10

A researcher discovered a DoS vulnerability in WhatsApp for Android/iOS/Web where a malicious payload embedded in a contact file could crash the victim's phone upon delivery. The vulnerability was patched by Facebook/WhatsApp after ~2 months, and the researcher received a $500 bounty.

WhatsApp Facebook Google Pratheesh P Narayanan Android iOS
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 2/10

Researcher discovered a DoS vulnerability in WhatsApp for iOS and Android by sending specially crafted Unicode characters and emojis in contact names that would crash the application, earning a $500 bounty from Facebook Security.

WhatsApp Facebook vishnuraj Aaron Bugcrowd
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

Stored blind XSS vulnerability in Telegram iOS app allowing arbitrary HTML/JavaScript execution via unvalidated HTML files in webview, enabling device fingerprinting, user activity tracking, and IP geolocation. Successfully exploited by uploading malicious HTML file that executed JavaScript to extract navigator object data and communicate with attacker server.

Telegram WhatsApp Facebook CVE-2018-UNKNOWN omespino iPhone 6 iPhone 7 iOS 11.2.5 iOS 11.2.6 Telegram iOS 4.7.1
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 5/10

A stored XSS vulnerability was discovered in Outlook.com's iOS browser implementation when viewing crafted PowerPoint files containing JavaScript protocol hyperlinks. The attack requires uploading a specially formatted .ppt file (saved as 97-2003 format) with a malicious javascript: URL, which executes when clicked in the email attachment viewer on iOS browsers.

outlook.com outlook.live.com Microsoft Google Chrome Safari Firefox Opera @omespino
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

Three XSS vulnerabilities discovered in ProtonMail for iOS: one via SVG onload in applewebdata origin, one via javascript URI requiring click interaction, and one via base64-encoded HTML embed in data origin. While XSSs do not allow email exfiltration, they enable JavaScript execution, privacy violations through tracking, phishing, and UXSS in privileged contexts.

ProtonMail Vladimir Metnew DOMPurify Cure53 CVE-2016-1764 Anatoly Andy Yen Safiler
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

CVE-2019-17004 is a semi-universal XSS vulnerability in Firefox for iOS that allowed attackers to execute JavaScript on arbitrary origins by exploiting insufficient checks on JavaScript execution via Location response headers, originating from the bookmarklets functionality. The vulnerability was also found in Brave for iOS and both vendors patched it after responsible disclosure.

CVE-2019-17004 Firefox for iOS Brave for iOS Safari Chrome Mozilla Cliqz
0x65.dev · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 2/10

Apple released security updates for older iOS and iPadOS versions (15.8.7 and 16.7.15) to address the Coruna exploit previously disclosed by Google, providing security fixes to devices unable to upgrade to iOS 17 or later.

Apple iOS 16.7.15 iPadOS 16.7.15 iOS 15.8.7 iPadOS 15.8.7 Coruna exploit Google iPhone 5s
macrumors.com · mgh2 · 21 hours ago · details · hn