they patched this vulnerability just because i gave them a weaponizable PoC, no need any user interaction. the patch is not finished, won't disclose at this moment
Dragging and dropping a file only gave access to one specific file and folder, plus it’s obvious that if you drag and drop a file, the target application will have access to it.
With Archive Utility’s plist, the attacker would’ve had unrestricted and persistent access to any file on the system, including hijacking apps
Anyway, we can agree to disagree. Apple considered it a real vulnerability and fixed it.