• 🌙 Community Spirit

    Ramadan Mubarak! To honor this month, Crax has paused NSFW categories. Wishing you peace and growth!

Browser Exploitation using possible LFI on Safari (1 Viewer)

Currently reading:
 Browser Exploitation using possible LFI on Safari (1 Viewer)

Recently searched:

donhoenix

Member
LV
0
Joined
Mar 16, 2023
Threads
2
Likes
0
Awards
1
Credits
441©
Cash
0$
so recently, I was doing some testing and noticed an odd behaviour on safari. while executing arbitrary javascript from a local html file, I was able to open a new finder window, note that this was not an upload window, the same directory containing the executed file was opened (see gif attached). this happened with all finder windows closed. my questions are:

1. Is there a possibility to exploit this behavior to write or open another file from the same directory outside the browser.
2. Is it possible this was a browser sandbox escape?, do you think it can be escalated?

I need help exploring these angles and testing on wider scenarios. hit me up if you are interested in working on browser level exploits and we can bounce ideas.

Ezgif 2 07b7d3e4d8
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Tips
Recently searched:

Similar threads

Users who are viewing this thread

Top Bottom