CHUCKREY.COM Avatar

45 Notes

Skype for iOS contains an XSS vulnerability that allows attackers steal information.

Executing arbitrary Javascript code is one thing, but I found that Skype also improperly defines the URI scheme used by the built-in webkit browser for Skype. Usually you will see the scheme set to something like, “about:blank” or “skype-randomtoken”, but in this case it is actually set to “file://”. This gives an attacker access to the users file system, and an attacker can access any file that the application itself would be able to access.”

Source: SUPEREVR SECURITY BLOG

Replies

Likes

  1. chuckrey posted this

 

Reblogs