Posted by josephgoyd via Fulldisclosure on Sep 08
Improper Input Validation in Siri Shortcuts and Shared Web Credentials
Enables Persistent Background Execution, Retry Storms, and Sandbox Extension Abuse
Date Discovered: August 20, 2025
Discovered By: Joseph Goydish II
Affected:
– iOS/macOS versions supporting Siri Shortcuts + Shared Web Credentials (SWC)
– Confirmed on iPhone 14 pro max / iOS 18.6.2
CWE Classification:
– CWE-20: Improper Input Validation
– CWE-184: Incomplete List of…
– Read More – Full Disclosure


