Collected research
Bypass for CVE-2024-9956 in Safari on iOS
A Shortcuts deep link can dispatch a FIDO URI through its error or cancellation callback after Safari blocks direct navigation to that scheme. The article explains the callback gadget and hybrid authentication flow. Session capture still requires an attacker device within Bluetooth range and the victim's approval; it does not extract passkey private keys.
Record
- Researcher
- Dennis Kniep
- Published by
- Dennis Kniep
- Date
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Dennis Kniep, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .