Mysk 🇨🇦🇩🇪

@mysk.bsky.social

We're two #iOS developers and occasional #security researchers on two continents. #CyberSecurity 🎬 https://youtube.com/@mysk 📝 https://mysk.blog

Many of you have asked for a way to support the Loupe project. We want to keep Loupe free of in-app purchases, so instead we’ve created a Buy Me a Coffee page for anyone who’d like to show their appreciation. ☕ buymeacoffee.com/mysk

Mysk

We are an independent cybersecurity and privacy research team focused on iOS and macOS.Our work explores security and privacy topics within the Apple ecosystem — including threat research, privacy inv

buymeacoffee.com

🚨 We're disclosing a macOS security bug that Apple says is not an issue. Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web, no password or warning is required. mysk.blog/2026/07/23/m...

Silent Replacement of Trusted macOS App Executables

A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications ...

mysk.blog

Oh, 1Password stores user profile pictures on their servers without authentication. Anyone who has the long URL, which also contains the account identifier, can access the picture. It's not a big deal, but a password manager should definitely be more careful. #privacy

Bild

Great news. Apple collects exhaustive analytics when you view apps in the App Store app. The detailed analytics is linked to your identity and there is no way to turn the massive data collection off. Now iPhone users can view apps anonymously in a browser www.macrumors.com/2025/11/03/a...

Apple Launches App Store for the Web

Apple launched a new App Store on the web today, allowing users to browse through and search for apps across all of its platforms. The updated...

macrumors.com

🏜️🎁 We accidentally found a security flaw in macOS Tahoe and earlier An attacker can trick a user into performing a simple yet common action that breaks the sandbox protection of any file (e.g iMessage database and Safari browsing data) giving any application permanent access to the target file