logo

BlackHat presentation demo vids: MobileMe

ID: c4b7040c-4481-58d2-b32f-680845ae77be

STIX ID: report--c4b7040c-4481-58d2-b32f-680845ae77be

Feed Name: SensePost Blog

Threat Score
55/100

Date Published: 2009-08-09

Date Updated: 2026-04-29

...
...

This write-up demonstrates weaknesses in Apple’s MobileMe service: a password-reset flow that can be abused using easily obtainable personal data (birthdate and secret-question answers) and an XSS vulnerability via an iPhone device name. The authors show how these flaws could enable account takeover and persistent access to mail, calendar, location and embedded JavaScript, illustrating the risk with a targeted demonstration against Steve Wozniak; the XSS was later patched by Apple.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.