Remix.run Logo
hnburnsy 3 hours ago

>We also identified additional code added when the actor attempts to infect a user using Chrome, where the x-safari-https protocol handler is used to open the page in Safari (Figure 4). This suggests that UNC6748 didn't have an exploit chain for Chrome at the time of this activity.

Thanks Apple for allowing the overriding of the user's default browser.