so recently, I was doing some testing and noticed an odd behaviour on safari. while executing arbitrary javascript from a local html file, I was able to open a new finder window, note that this was not an upload window, the same directory containing the executed file was opened (see gif attached). this happened with all finder windows closed. my questions are:
1. Is there a possibility to exploit this behavior to write or open another file from the same directory outside the browser.
2. Is it possible this was a browser sandbox escape?, do you think it can be escalated?
I need help exploring these angles and testing on wider scenarios. hit me up if you are interested in working on browser level exploits and we can bounce ideas.
1. Is there a possibility to exploit this behavior to write or open another file from the same directory outside the browser.
2. Is it possible this was a browser sandbox escape?, do you think it can be escalated?
I need help exploring these angles and testing on wider scenarios. hit me up if you are interested in working on browser level exploits and we can bounce ideas.