Note
Due to the sandbox of the affected app, it is only possible to write to /var/mobile/Containers
, and you cannot overwrite file with this, hence Apple closed the report.
@verygenericname told me he found an arbitrary write to /var/mobile/Containers
, using the Files app, with the following steps:
- create a folder,
- put a file inside it,
- move the file to trash,
- replace the folder with a symlink anywhere in /var/mobile/Containers/,