Remote Mac Exploitation via Custom URL Schemes
objective-see.com
objective-see.com
* MacOS automatically registers an application as the default handler for any custom URL schemes it declares, as soon as the app is downloaded (this happens automatically when the app hits the hard drive)
* Such custom URL schemes linked to malicious app may be opened via javascript automatically on a webpage, leading to the app execution by the system
* The system asks for permission to launch the app the first time. The name of the app as displayed in the permission box is app-controlled, so it can spoof its identity or use a cute name with emojis to make it less suspicious (as per the article)
Small point, but one I think is important, is you’ll be asked not once, but twice for confirmation. The first confirmation is for the custom url scheme, the second confirmation is for file quarantine for the newly downloaded app.
While I think the default of “opening safe files” is utterly bat shit stupid, Apple has done a fair amount here to block this “attack” vector otherwise. It’s asinine to me this “attack” would work on a security minded user as the article indicates the presenter said, but I guess the adage that “everyone makes mistakes sometimes” explains it.
So as long as the app is signed, there are no secondary prompts from gatekeeper
What you said is untrue in High Sierra and maybe other versions. Go out and download a signed executable. If I download and execute a signed package from the Internet, I receive no warning. If that package installs a URL scheme helper, I always receive "would you like to run xxxxxx" from Safari.
The article even says gatekeeper does not come into play with signed apps. So you are refuting the article's accuracy?
1: https://support.mozilla.org/en-US/kb/profile-manager-create-...
2: https://support.google.com/chrome/answer/2364824?co=GENIE.Pl...
and surrender your privacy to Google, have no functioning private browsing etc. makes me to rethink about objective-see tools.
This hasn't been true for a long time, the automatically open 'safe' files option has been turned off by default for years now.
Though the option should be removed all together really.