@mjtsai The bugs are in the apps. The malicious code is delivered multiple ways. Wikipedia has an article on RCE. https://en.wikipedia.org/wiki/Arbitrary_code_execution …
@mjtsai @drewthaler Do you have an example of that? Because LaunchServices handles openFile.
-
-
@rosyna@drewthaler Not handy. DTS eventually explained it to me; they were initially unaware, too. I fear more undocumented cases like this -
@mjtsai@drewthaler Because restrictions on openFile: are mostly handled by Gatekeeper, not the sandbox. - View other replies
-
@rosyna@drewthaler Similar issue in that some AppleScripts don’t work from sandbox, even when run using NSUserAppleScriptTask. -
@mjtsai@drewthaler In both cases, you need to use security-scoped bookmarks and startAccessingSecurityScopedResource - View other replies
-
@rosyna@drewthaler Perhaps security-scoped bookmarks are supposed to work in this case, but in practice they didn’t.
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Rosyna Keller
Drew Thaler
Michael Tsai