Apple Reportedly Patches XSS Vulnerability on iCloud’s Website

In a blog post shared by ZDNet, security researcher Vishal Bharad claims that he found a bug that would have allowed a hacker to inject a virus or malicious script onto Apple’s ‌iCloud‌ website.

According to Bharad, the vulnerability consisted of creating a Pages or Keynote document on the ‌iCloud‌ website with the name field containing the XSS payload. Sharing the document with another user, creating a change, saving, and then clicking “Browse All Versions” under Settings would have triggered the XSS payload.

Given the vulnerability revolved around the ‌iCloud‌ website, it’s not linked to a recent software update and has reportedly been patched by Apple server-side. Bharad says he submitted the issue to Apple on August 7, 2020, and received a $5,000 bounty on October 9, 2020. We’ve reached out to Apple for comment and we’ll update if we hear back.Tags: security, iCloud
This article, “Apple Reportedly Patches XSS Vulnerability on iCloud’s Website” first appeared on MacRumors.com

Discuss this article in our forums

MacRumors-All?d=6W8y8wAjSf4 MacRumors-All?d=qj6IDK7rITs

Related posts

Latest posts

The Lenovo Legion gaming tablet was just released. Here’s why it is already on sale

The Lenovo Legion Tab Gen 3 is just released and is already on sale. What's up with that?

Watch the YouTube video that launched the site exactly 20 years ago

It lacks the high production values present in so many of today’s YouTube videos, but then Jawed Karim wasn’t aiming for anything slick. It was merely a little something to launch his new video streaming site. Filmed at San Diego Zoo by a friend and posted on April 23, 2005, Karim says straight to camera: […]

Watch the YouTube video that launched the site exactly 20 years ago

It lacks the high production values present in so many of today’s YouTube videos, but then Jawed Karim wasn’t aiming for anything slick. It was merely a little something to launch his new video streaming site. Filmed at San Diego Zoo by a friend and posted on April 23, 2005, Karim says straight to camera: […]

Asus CX14, CX15 Chromebook Plus announced with big displays and Google AI

Asus announced its next wave of CX14 and CX15 Chromebooks for consumers.

Fairphone is doing its part to make the world a better place. Is it enough?

It's easier for a small company to do the right thing. We need to see the same from the tech

Google paid Samsung hefty amounts of money to preinstall Gemini

Google is paying Samsung to preinstall Gemini on its devices

Rumors allege a Galaxy Tab S10 ‘Lite’ is on the way, and a Tab S11 series shake-up

Samsung is allegedly planning a new "Lite" tablet release and another shake-up for its Tab S11 series.

Google’s Earth Day 2025 Doodle shows the many sides of our big blue planet

Google explains the significance of its Earth Day 2025 doodle.

YouTube Music tests new Spotify-like lyrics sharing feature

YouTube Music is testing a new feature that allows users to share song lyrics on social media. It should likely

Most top-selling Meta Quest games all share one key trait

The top 50 best-selling Meta Quest games of all time have just been revealed, and the vast majority sport one