vendor:
Mac OS X
by:
filippo.cavallarin@wearesegment.com
N/A
CVSS
N/A
DOM Based XSS
79
CWE
Product Name: Mac OS X
Affected Version From: 10.12
Affected Version To: 10.10
Patch Exists: YES
Related CWE: N/A
CPE: o:apple:mac_os_x
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OS X
2017
Mac OS X Local Javascript Quarantine Bypass
Mac OS X contains a vulnerability that allows the bypass of the Apple Quarantine and the execution of arbitrary Javascript code without restrictions. The vulnerability is in one html file, part of the Mac OS X core, that is prone to a DOM Based XSS allowing the excution of arbitrary javascript commands in its (unrestricted) context.
Mitigation:
Apple's Quarantine works by setting an extended attribute to downloaded files (and also to files extracted from downloaded archive/image) that tells the system to open/execute those files in a restricted environment.