
bl_sbx
itunesstored & bookassetd sbx escape
binary-exploitationeducationexploitation+3
32710 months ago

itunesstored & bookassetd sbx escape

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

CVE-2022-46718: an app may be able to read sensitive location information.

CVE-2023-40429: An app may be able to access sensitive user data.

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.