Hey! There are dozens of us!
Hey! There are dozens of us!
Was CVE-2024-44133 Already Exploited?
After concocting their exploit, Microsoft started scanning customer environments for activity that aligned with what they’d found. On one device, lo and behold, they spotted something quite closely resembling what they were looking for.
It was a program digging into the victim’s Chrome configuration settings, adding approval for microphone and camera access to a specific URL. It also did more: gathering user and device information, laying the groundwork for a second-stage payload.
I’m not sure if this article is disingenuous or if I’m just confused… but it states when MS scanned their customers’ environments, they discovered malware making changes to the Chrome config. And the Safari CVE was patched in September. So we don’t have proof of this happening in the wild then?
What’s more, the Safari exploit requires making changes to a protected directory. But no indication of how that is done by just the browser exploit. Did the attackers already have access to the machine? If so, this article is a nothing burger.
This article boils down to “man enables feature, is slightly surprised when feature functions.”
The icon and hover to reveal previous title has been available in the extension for a long while.
You can on any iOS device without jailbreaking. Look into AltStore or Sidestore. The caveat is that you can only sign 3 apps at a time, and must resign these apps every week - which is done over your WiFi to a PC running AltStore server.
If you have a $99/year Apple developer account, you can use AltStore to sign as many apps as you like, and you only need to resign once per year.