Hacker News new | ask | show | jobs
by tptacek 3754 days ago
No, it is not exploitable.
3 comments

Yeah, at worst a misconfigured system where non-root users have access to sniff it could be attacked.

Short of that level of extreme misconfiguration, you need admin, which means all bets are already off as you can keylog, inject libs, patch the executable, whatever you please really.

They could do more to protect this, but anything more would be a half-measure of no real use against a targetted attack at least.

In general it depends on the protocol that is used for communication. If it for example were not authenticated HTTP, it could be remotely exploitable by a website that a user visits.
But could it leak something - lets say antivirus or firewall with heuristics picks up the traffic and sends it for analysis?
Don't install antivirus software on OS X. Who knows what crazy shit it might do to your system?