Unveiling the Apple CVE-2024-40834 - A Shortcut to the Bypass Road
Objective-See Foundation via YouTube
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Become an AI & ML Engineer with Cal Poly EPaCE — IBM-Certified Training
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Watch a 19-minute conference talk exploring a critical security vulnerability (CVE-2024-40834) discovered in Apple's Shortcuts application across iOS, WatchOS, MacOS, and VisionOS platforms. Learn how manipulating specific functionalities enables arbitrary command execution on MacOSX systems while bypassing built-in security features, and allows unauthorized file access across all Apple operating systems with potential data leakage to remote hosts. Understand the implications of this vulnerability for drive-by-download phishing attacks, where malicious payloads can be distributed through Apple's native infrastructure with legitimate signatures and without triggering security alerts. Presented by Marcio Almeida, a Security Specialist at Tanto Security with over 10 years of experience in penetration testing, code review, and exploit development, this talk from Objective-See Foundation's conference provides valuable insights into potential exploitations within the Apple ecosystem and emphasizes the importance of developing protective measures for user safety.
Syllabus
#OBTS v7.0: "Unveiling the Apple CVE-2024-40834 - A 'shortcut' to the Bypass Road" - Marcio Almeida
Taught by
Objective-See Foundation