According to Odaily, a significant zero-click vulnerability chain has been identified in macOS, specifically within the calendar invitation feature. This discovery was disclosed by 23pds, the Chief Information Security Officer of SlowMist, on the X platform. The vulnerability allows attackers to execute a series of actions without any interaction from the user, posing a serious security threat.
SlowMist founder, Yuxian, further elaborated on the issue, highlighting the potential risks associated with this vulnerability. He noted that the attack chain could enable unauthorized access to sensitive information stored on Apple computers, such as mnemonic phrases from photo albums. The alarming aspect of this vulnerability is that the affected users only needed to glance at their calendar for the attack to be successful.