
Sign up to save your podcasts
Or


With iOS v11, the iOS camera app is continually looking for QR codes and, when found, displays a confirmation message prompting the user whether they wish to open Safari at that URL. But there's a URL parsing error which allows the true URL domain to be hidden behind a spoofed display URL. By exploiting the URL parsing flaw one domain can be shown while another entirely different domain is visited.
Full episode at twit.tv/sn657
Bandwidth for TWiT Bits is provided by CacheFly.
By TWiT4.7
2323 ratings
With iOS v11, the iOS camera app is continually looking for QR codes and, when found, displays a confirmation message prompting the user whether they wish to open Safari at that URL. But there's a URL parsing error which allows the true URL domain to be hidden behind a spoofed display URL. By exploiting the URL parsing flaw one domain can be shown while another entirely different domain is visited.
Full episode at twit.tv/sn657
Bandwidth for TWiT Bits is provided by CacheFly.

9 Listeners

34 Listeners

109 Listeners

6 Listeners

139 Listeners

29 Listeners

96 Listeners

35 Listeners

72 Listeners

116 Listeners

94 Listeners

24 Listeners

50 Listeners

15 Listeners

10 Listeners

9 Listeners

0 Listeners

28 Listeners

31 Listeners

0 Listeners