/CoreFollowUpAttack

CoreFollowUp phishing attack on macOS

Primary LanguageObjective-CBSD 2-Clause "Simplified" LicenseBSD-2-Clause

CVE-2022-22660: CoreFollowUp phishing attack on macOS

This project is the proof of concept detailing the macOS bug that would allow processes to perform a very effective phishing attack against users.

It is only fully effective when running on macOS versions before 11.3.

The full writeup can be read on my blog.

Note: this is provided for educational purposes only and should only be used against your own devices or devices of people who have given you explicit permission to do so.