safari

2 articles
sort: new top best
clear filter
0 7/10

A bug bounty hunter discovered a stored XSS vulnerability on m.uber.com that could be chained with an arbitrary cookie installation vulnerability on business.uber.com to steal oauth2 tokens and compromise any logged-in Uber user's account. The exploit involved injecting malicious cookies via unsanitized server responses and using the XSS payload to extract sensitive authentication cookies from victims.

Uber m.uber.com business.uber.com HackerOne Jack httpsonly
httpsonly.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 2/10

A Safari extension developer who filed 82 new Safari bugs in 2025 through WebKit Bugzilla and Apple Feedback Assistant shares statistics showing only ~32 were fixed, and argues Safari's software quality is deteriorating based on increasing unfixed bug accumulation.

Apple WebKit Safari Bugzilla Feedback Assistant
lapcatsoftware.com · zdw · 1 day ago · details · hn