Security

PoC published for CVE-2024-54498 macOS sandbox escape patched in macOS Sequoia 15.2

MacBook Pro Matrix Hack banner image.

Apple device security nerds, unless they’ve been living under a rock, have probably heard about CVE-2024-54498, or perhaps better known as the sharedfilelistd vulnerability. It was one of several vulnerabilities that Apple claims to have patched in macOS Sequoia 15.2, macOS Sonoma 14.7.2, and macOS Ventura 13.7.2, citing details shared on Apple’s About the security content of macOS Sequoia 15.2 web page.

Prevent over-shoulder passcode snooping attacks with the Rode jailbreak tweak

Rode banner.

One of my biggest qualms with the Lock Screen on any iPhone or iPad is the fact that the number pad for passcode entry always has the same layout. This means that even if someone who’s glancing over your shoulder doesn’t know exactly what numbers you’re tapping on, they can instead easily memorize the positions of the number buttons you tap on to gain access to your device.

How to change the root user password on a rootless jailbreak with NewTerm

How to change root user password banner image.

We previously showed you how you can change the root user password on your jailbroken handset with an on-device terminal app like NewTerm. But since then, the process has changed slightly, especially if using modern rootless jailbreaks on iOS or iPadOS 15 and later, such as Dopamine or palera1n. Fortunately, we will share the updated process with you in today’s tutorial.

iCloud Passwords extension that brings iCloud Keychain auto-fill to Firefox for macOS now owned by Apple

iCloud Passwords extension for Firefox on macOS.

As someone who has been using the Mozilla Firefox web browser on their Mac and Windows computers for nearly two decades, I’ve never been able to comfortably switch to Apple’s Safari web browser on my Mac. This is, in part, because of the higher quality extensions available for Firefox. But one gripe that I’ll admit is Safari’s deep integration with Apple’s Passwords app makes entering logins a breeze.