Posted by josephgoyd via Fulldisclosure on Sep 08
[Zero-Day] AppleMediaServices Fail-Open Auth Bypass (All Platforms)
Overview:
A criticalzero-dayvulnerability in AppleMediaServices (AMS)
affects all Apple platforms — iOS, macOS, tvOS, and watchOS.
When AMS fails to fetch its remote “Bag” config file, it disables
Mescal and Absinthe request signingwithout warning, falling back to
unsigned, unauthenticated API requests.
This fail-open condition enables request tampering, replay…
– Read More – Full Disclosure



