| X | https://x.com/mysk_co |
| Blog | https://mysk.blog |
| YouTube | https://youtube.com/@mysk |
| Old Mastodon | https://defcon.social/@mysk |
| X | https://x.com/mysk_co |
| Blog | https://mysk.blog |
| YouTube | https://youtube.com/@mysk |
| Old Mastodon | https://defcon.social/@mysk |
FYI: FaceTime calls expose your IP to other participants. In Settings โ Privacy & Security โ App Privacy Report you can see recent call IPs, and others can see yours. Unlike Signal and WhatsApp, Apple offers no option to relay calls through its servers to hide your IP
Same experiment on iOS:
๐๐จ New blog post: How a bug in Archive Utility allowed access to protected app data (including iMessage and WhatsApp chats, and Safari cookies) without any permissions.
The bug could also be exploited to hijack installed apps such as Signal and 1Password to perform phishing attacks.
Apple fixed the issue in macOS 26.4 as CVE-2026-28910, five months after we reported it
macOS Bug Lets Attackers Hijack Background Apps to Spy on Clipboard โ Fixed in 26.4 (CVE-2026-28910)

macOS Security: Archive Utility bug can expose Safari, Messages, and WhatsApp data - CVE-2026-28910

macOS Security: Archive Utility Bug Could Expose 1Password Secrets โ Fixed in 26.4 (CVE-2026-28910)

macOS Archive Utility Bug Could Let Attackers Hijack Signal SessionsโFixed in 26.4 (CVE-2026-28910)
