RSSAmplifier

Blog

Snoolie's Blog

My Blog!

snoolie.gayRSS feed ↗10 posts

Latest posts

(CVE-2024-27876) libAppleArchive: Arbitrary File Write

libAppleArchive arbitrary file write vulnerability

What is a 0day?

Two useless bugs and discussion of what makes a 0day.

Archive Utility: Race Condition during Extraction

Archive Utility Race Condition that existed until macOS 15.

The iOS 8 IOHIDFamily bug that wasn't patched.

1day that was patched iOS 12 in a method TaiG's 8.1.2 jailbreak used.

shortcut-sign and the future of libshortcutsign

Open-Source Cross-Platform Signed Shortcut CLI.

(CVE-2024-27821) WorkflowKit: Race Vulnerability in Extraction/Generation

A look at CVE-2024-27821. Patched in macOS 14.5.

Hidden Actions: The Most Dangerous Shortcuts Vulnerability

A look back at the most dangerous vulnerabilty for Shortcuts, and how I fucked up and never got credit.

CVE-2021-30763

A look back at the first CVE I ever got credited for. Partially patched iOS 14.6, fully patched 15.0.

Reversing Contact Signed Shortcuts

Still proud of this one. IMO, the de facto writeup available for contact signed shortcuts. If you know if any others, tell me! This was originally on GitHub but I transfered it over to here.

Extract Archive Arbitrary Write Vulnerability

iOS 15 Shortcuts 0day I publicly disclosed since I didn't know how bug bounty worked at the time.