Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-26766 PoC — Apple TV 4K和Apple TV HD 信任管理问题漏洞

Source
Associated Vulnerability
Title:Apple TV 4K和Apple TV HD 信任管理问题漏洞 (CVE-2022-26766)
Description:A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.
Description
Proof-of-concept for CVE-2022-26766 on macOS 12.3.1
Readme
Demo for Linus Henze's CoreTrust bug (CVE-2022-26766, CoreTrust allows any root certificate)

See https://worthdoingbadly.com/coretrust/ for usage.
File Snapshot

[4.0K] /data/pocs/6d6957a22e62d10395157f4e00d7172c5fbc97fc ├── [4.0K] badcert │   ├── [2.9K] certificate_chain.pem │   ├── [1.1K] codeca_certificate.csr │   ├── [1.5K] codeca_certificate.pem │   ├── [ 41] codeca_certificate.srl │   ├── [1.7K] codeca_key.pem │   ├── [1.1K] dev_certificate.csr │   ├── [4.9K] dev_certificate.p12 │   ├── [1.5K] dev_certificate.pem │   ├── [1.7K] dev_key.pem │   ├── [1.9K] makecerts.sh │   ├── [1.4K] root_certificate.pem │   ├── [ 41] root_certificate.srl │   └── [1.7K] root_key.pem ├── [ 62] build2.sh ├── [ 56] build.sh ├── [ 340] build_spawn_root.sh ├── [ 18K] CTEvaluate.h ├── [4.0K] fakeiphonecert │   ├── [2.9K] certificate_chain.pem │   ├── [1.1K] codeca_certificate.csr │   ├── [1.5K] codeca_certificate.pem │   ├── [1.7K] codeca_key.pem │   ├── [1.2K] dev_certificate.csr │   ├── [5.0K] dev_certificate.p12 │   ├── [1.5K] dev_certificate.pem │   ├── [1.7K] dev_key.pem │   ├── [1.8K] makecerts.sh │   ├── [1.4K] root_certificate.pem │   └── [1.7K] root_key.pem ├── [6.2K] libmis.tbd ├── [2.5K] littlect.m ├── [1.3K] littlemis.m ├── [2.9K] littlemis.txt ├── [ 148] README.md ├── [ 242] spawn_root.entitlements └── [ 960] spawn_root.m 2 directories, 35 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →