SafeExamBrowser / seb-mac

Safe Exam Browser for macOS and iOS
https://www.safeexambrowser.org/macosx
96 stars 39 forks source link

MacOS Shortcuts #391

Closed Radestijn closed 2 months ago

Radestijn commented 2 months ago

Description: If you make a shortcut on macOS a title and set it to the menu bar you can click on the menu bar and see all the titles from all the shortcuts you have pinned in the menu bar. The title of the shortcut can be a translation or the answer for a question.

How to reproduce:

  1. Open the shortcuts app on your MacOS device
  2. Make a shortcut with the title nothing has to be in the shortcut
  3. click on the info button in the top right
  4. click on pin to menu bar
  5. press enter to safe the shortcut
  6. test it and you can click on it to see the title from all the shortcuts

Expected behavior you can't see the menu bar/ can't click on anything in the menu bar.

Versions Macbook = Sonoma 14.4.1 SEB = 3.3.2

danschlet commented 2 months ago

Thank you for reporting this Shortcuts exploit.

You can actually disable the menu bar, please check the manual (User Interface panel). Also by using the AAC Assessment lockdown mode (Security panel), the menu bar is disabled by default.