4.9 • 696 Ratings
🗓️ 21 November 2024
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, November 21st, |
0:04.0 | 2024 edition of the Sands and at Storms, Stormcast. |
0:09.0 | My name is Johannes Ulrich, and I'm recording from Singapore. |
0:14.0 | Today we got two Apple vulnerabilities to start out with. |
0:18.0 | These vulnerabilities were patched yesterday and they address |
0:23.6 | two vulnerabilities that are already being exploited in the wild. The first of the vulnerability |
0:29.8 | affects JavaScript core and could of course be triggered by visiting a malicious webpage, |
0:36.1 | which then leads to arbitrary code execution. |
0:39.2 | The second vulnerability similarly affects WebKit. Also, of course, exploitable by visiting |
0:45.5 | a malicious website. It's a little bit different, a little bit interesting vulnerability here. |
0:50.2 | It says it's a vulnerability in the cookie management system that could lead to cross-site |
0:55.7 | scripting. |
0:56.7 | So sounds like if an attacker is able to create a particular cookie for your browser that |
1:03.5 | could potentially modify content on the web page. |
1:07.8 | Not only sure how this will work, we don't have a lot of details or any |
1:11.9 | details really about these vulnerabilities other than Google reported them as already being |
1:18.8 | exploited. There are updates available for Safari as well as for Apple's operating systems, |
1:26.5 | which of course then patch the WebKit part as well. |
1:31.5 | The Safari patch is usually just meant for older operating systems. |
1:36.7 | And of course, this flaw being already exploited means that you probably should apply this |
1:41.8 | update soon. |
1:47.1 | And talking about vulnerabilities that are already being exploited, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.