Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Cross-Site Escape - Pwning macOS Safari Sandbox the Unusual Way

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk examines three macOS Safari sandbox escape techniques that exploit privileged WebViews, inter-process communication, URL schemes, and legacy components. It includes case studies involving local file disclosure and arbitrary native code execution without memory corruption.

Syllabus

Intro
Comparation
TOCTOU Without Racing
Web Content Case Study
Timeline for Web Content
Dashboard Widgets
Turning to Arbitrary Widget installation
Sandbox Escape
Problems
Triggering Execution
Hard Coded Trusted Schemes
Legacy Help
Sandbox is...gone
(Failed) Local File Disclosure
Some Drama
CVE-2020-9979: We Got Trust Issue
Dictionary App
Arbitrary File Execution
Local File Execution
How do we jump to Dictionary?
Jump to Dictionary.app
Summary
Takeaways

Taught by

Black Hat

Reviews

Start your review of Cross-Site Escape - Pwning macOS Safari Sandbox the Unusual Way

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.