DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)

Post by Shane1145 »

DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices) (High) (CVE-2022-32212, CVE-2018-7160)
The fix for CVE-2022-32212, covered the cases for routable IP addresses, however, there exists a specific behavior on macOS devices when handling the http://0.0.0.0 URL that allows an attacker-controlled DNS server to bypass the DNS rebinding protection by resolving hosts in the .local domain.


https://hackerone.com/reports/1714979
Post Reply