Sunday, February 23, 2025
HomeAppleiOS/macOS Webcam Can be Hacked With A Single Click On Malformed Link...

iOS/macOS Webcam Can be Hacked With A Single Click On Malformed Link – Hacker Rewarded $75,000

Published on

SIEM as a Service

Follow Us on Google News

By just making the users visiting a link, an attacker can hack the users’ iOS/macOS Camera using zero-day bugs in Safari.

With iOS and macOS camera security model every app needs to assigned permission manually but Apple’s own app such as Safari gets access by default.

Security researcher Ryan Pickren discovered seven new vulnerabilities with Safari browser that allows attackers to access your device’s camera, microphone, or location, and in some cases, saved passwords as well.

iOS/macOS Webcam

Pickren said that Safari not using the method of the origin to keep track of the open website, “I deduced that Safari was likely running a Generic URI Syntax parser against all open windows to get the URIs’ hostnames, then doing some extra parsing on those.”

Exploiting Bugs to Access Camera

He started exploiting using javascript: data: and about, but that fails, but while parsing file: which specified for remote or FTP purpose(file://host.example.com/Share/path/to/file.txt).

iOS/macOS Webcam

Safari parses it as a normal file URI, “the page actually accepted this URI as valid and reloaded the same content. Which means I just changed the document.domain using this really dumb trick. (CVE-2020-3885).”

So now the Safari browser thinks the website connected is skype9.0com, by opening the local file attackers can run a malicious script and gain access to Camera, Microphone, and Screen Sharing.

He found another bug (CVE-2020-9784 & CVE-2020-3887) to bypass the auto-download prevention in the Safari browser.

By using blob://skype.com URI a popup can be triggered and can be used to execute the arbitrary JavaScript.

Trying all chain of bugs can grant access to iOS/macOS camera, microphone, or location, and in some cases, saved passwords.

Following are the seven bugs

CVE-2020-3852 – A logic issue was addressed with improved validation.

CVE-2020-3864 – A DOM object context may not have had a unique security origin

CVE-2020-3865 – A top-level DOM object context may have incorrectly been considered secure

CVE-2020-3885 – File URL processed incorrectly.

CVE-2020-3887 – A download’s origin may be incorrectly associated

CVE-2020-9784 – Malicious iframe use another website’s download settings

CVE-2020-9787 – Hostnames with a dash (-) and period (.) are ignored

iOS/macOS Webcam

All the vulnerabilities patched in January and March updates. The researcher receives $75,000 for the bug submission.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

New Zhong Stealer Malware Exploit Zendesk to Attack Fintech and Cryptocurrency

A newly identified malware, dubbed Zhong Stealer, has emerged as a significant threat to...

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

CISA Issues Seven ICS Advisories Highlighting Critical Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released seven Industrial Control Systems (ICS)...

Fedora Linux Kernel Flaw Exposed Sensitive Data to Attackers

A newly discovered vulnerability in the Fedora Linux kernel, identified as CVE-2025-1272, has raised...

IBM OpenPages Flaw Exposed Authentication Credentials to Attackers

IBM recently disclosed multiple vulnerabilities in its OpenPages platform, a tool widely used for...