Apple iOS Activation Flaw Enables Injection of Unauthenticated XML Payloads

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

Apple iOS Activation Flaw Enables Injection of Unauthenticated XML Payloads

Post by Shane1145 »

A severe vulnerability in Apple’s iOS activation infrastructure has been uncovered, posing a significant risk to device security during the setup phase.

This flaw, identified in the iOS Activation Backend at the endpoint https://humb.apple.com/humbug/baa, allows attackers to inject unauthenticated XML .plist payloads without any form of sender verification or signature validation.

https://gbhackers.com/apple-ios-activat ... injection/
Post Reply