[0-Day] CVE-2022-46875 - Mozilla Firefox Download Protection Bypass Vulnerability Original Write up : SSD ADVISORY – MACOS MOZILLA FIREFOX DOWNLOAD PROTECTIONS WERE BYPASSED Summary A vulnerability in Mozilla Firefox has been found to not show an executable file warning when downloading .atloc and .ftploc files, which can run commands on a user’s computer. Credit Dohyun Lee, working for SSD Labs Korea. CVE CVE-2022-46875 Vendor Response The vendor has released patches availab..
[0-Day] CVE-2022-32787 - Apple Safari ICU Out-Of-Bounds Write Vulnerability Original Write up : SSD Advisory – Apple Safari ICU Out-Of-Bounds Write TL;DR An Out-Of-Bounds Write vulnerability exists in Apple Safari ICU components libicucore.A.dylib [icu::FormattedStringBuilder::insert]. This library is called when Safari handles the Intl.ListFormat().format function. Vulnerability Summary A vulnerability in Apple Safari ICU components allows an attacker to trigger an OOB..