Posted by josephgoyd via Fulldisclosure on Sep 08
Improper Input Validation in Siri Shortcuts and Shared Web Credentials
 Enables Persistent Background Execution, Retry Storms, and Sandbox Extension Abuse
Date Discovered: August 20, 2025
 Discovered By: Joseph Goydish II
Affected:
 – iOS/macOS versions supporting Siri Shortcuts + Shared Web Credentials (SWC)
 – Confirmed on iPhone 14 pro max / iOS 18.6.2
CWE Classification:
 – CWE-20: Improper Input Validation
 – CWE-184: Incomplete List of…
 –  Read More  – Full Disclosure 

 
			

