Jemand versucht, Menschen über Apple Podcasts zu „hacken“ | Seit Monaten öffnet Apple Podcasts wahllos Podcasts zu Spiritualität und Religion und leitet Hörer in einem Fall auf eine potenziell bösartige Website weiter

    https://www.404media.co/someone-is-trying-to-hack-people-through-apple-podcasts/

    Share.

    11 Kommentare

    1. A number of the issues identified:

      >Something very strange is happening to the Apple Podcasts app. Over the last several months, I’ve found both the iOS and Mac versions of the Podcasts app will open religion, spirituality, and education podcasts with no apparent rhyme or reason. Sometimes, I unlock my machine and the podcast app has launched itself and presented one of the bizarre podcasts to me. On top of that, at least one of the podcast pages in the app includes a link to a potentially malicious website.
      >
      >…
      >
      >“The most concerning behavior is that the app can be launched automatically with a podcast of an attacker’s choosing,” Patrick Wardle, a macOS security expert and the creator of Mac-focused cybersecurity organization Objective-See, said. “I have replicated similar behavior, albeit via a website: simply visiting a website is enough to trigger Podcasts to open (and a load a podcast of the attacker’s choosing), and unlike other external app launches on macOS (e.g. Zoom), no prompt or user approval is required.”
      >
      >To caveat straight away: this isn’t that alarming. This is not the biggest hack or issue in the world. But it’s still very weird behavior and Apple has not responded to any of my requests for comment for months. “Of course, very much worth stressing, on its own this is not an attack,” Wardle continued. “But it does create a very effective delivery mechanism if (and yes, big if) a vulnerability exists in the Podcasts app.
      >
      >…
      >
      >Overall, the whole thing gives a similar vibe to Google Calendar spam, where someone will sneakily add an event to your calendar and include whatever info or link they’re trying to spread around. I remember that being a pretty big issue a few years ago.
      >
      >Apple did not acknowledge or respond to five emails requesting comment.

      Hopefully even though unresponsive to the journalist, Apple is working to manage these risks on their platform.

    2. Okay, so this kept happening to me but it was opening Apple Music repeatedly. I’d close it and it would open again. I could not figure out what was going on. That was this past summer.

    3. heitarlaugar on

      It’s gotta be 1) Safari is set to allow websites to open applications and 2) malicious sites doing just that. Part of the problem is people’s comfort with going everywhere/anywhere online, some sites simply aren’t safe.

    4. Yup, one step more sneaky than one-sided news outlets pretending to be unbiased, but shouldn’t be a surprise.

    5. Adept-Target5407 on

      Ha. I beat the hackers to it. I have an automation that runs when I connect to a specific Bluetooth speaker in my office that automatically open Apple Music and starts playing my favorites playlist.

    6. This is probably pretty core components at this point that are so rooted in the system they can’t be changed easily

    Leave A Reply