This site uses cookies to provide you with a more responsive and personalized service. By using this site and clicking on the "Accept" button, you agree to our use of cookies. Please read our Privacy Policy for more information on the types of cookies we use and how to delete or block them.
Learn more
Browse and search by keywords or use filters to find sessions that interest you most. Can’t make a session time? Don’t worry. All sessions will be made available in the virtual platform for 60 days post-JNUC.
CVE-2022-22616 - A Deep Dive Into the Discovery of a Safari Vulnerability [1173]
Login to view this video
, Detections Developer II, Jamf
Jamf security researchers discovered a vulnerability earlier this year and reported their findings to Apple which is now patched and assigned CVE-2022-22616. Join Ferdous Saljooki from the Jamf Threat Labs team to take a deep dive into vulnerability analysis.
Gatekeeper is a security feature built into macOS that prevents the user from executing potentially malicious and/or unwanted software. It is designed to ensure that only trusted software launches on a user’s system by verifying notarization and code signing information.
A vulnerability existed in the Safari browser that allowed a specially crafted zip to bypass all checks performed by Gatekeeper. This allowed for the execution of an application that was completely unsigned and un-notarized. Join us on this journey through macOS internals and research.