Remix.run Logo
jwatzman 2 hours ago

Not sure I understand the risk here, and seem to agree with Apple this is a non-issue. You already have code execution in order to exploit this. You don’t get the cryptographic identity of the victim app so you can’t steal keychain secrets. How is this any different than just bundling your own second-stage malware with a victim bundle ID, then using your existing code execution to remove the quarantine flag and then run the second-stage malware? Or just doing the evil things with your existing code execution?

neuralkoi an hour ago | parent | next [-]

I would use "Defense in Depth" as an argument to addressing this issue.

33 minutes ago | parent | prev [-]
[deleted]