Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Microsoft found a critical security bug in macOS that could have many users worried

  • May 31, 2023
Total
0
Shares
0
0
0


Microsoft found a critical security bug in Apple’s macOS that could have many users worried.

The vulnerability is tracked as CVE-2023-32369. It has been dubbed Migraine, and allows threat actors with root privileges to bypass System Integrity Protection (SIP), essentially being given the opportunity to install malware that cannot be deleted from the endpoint. Furthemore, the flaw allows threat actors to work around Transparency, Consent, and Control (TCC) feature, and access sensitive data. 

The bug has since been patched across the Apple ecosystem, with users told to apply the fix as soon as they can.

Arbitrary code execution

System Integrity Protection is a feature on Apple devices that restricts the root account. Also known as “rootless”, the feature makes the OS kernel put checks on the root user’s access, preventing it from making certain changes to key folders and files. Devices with SIP only allow Apple-signed processes, or those with special Apple entitlements (think patches and updates), to make changes to protected components and elements.

The only way to disable SIP is to have physical access to the target endpoint, making compromise through this avenue almost impossible. Still, Microsoft’s team found a way to bypass SIP through the Migration Assistant, a tool that allows users to migrate their data to a new device. 

“By focusing on system processes that are signed by Apple and have the com.apple.rootless.install.heritable entitlement, we found two child processes that could be tampered with to gain arbitrary code execution in a security context that bypasses SIP checks,” Microsoft’s researchers explained.

In other words, threat actors could add malware to SIP’s exclusion list and then, without botting from macOS Recovery, automate the migration process. 

Apple has fixed the vulnerability in macOS Ventura 13.4, macOS Monterey 12.6.6, and macOS Big Sur 11.7.7, so make sure to bring your operating system up to date immediately.

Via: BleepingComputer


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Flighty’s tool will help you connect with fellow WWDC attendees

  • May 31, 2023
View Post
Next Article
  • News

What not to share with ChatGPT

  • May 31, 2023
View Post
You May Also Like
View Post
  • News

‘Lied to the World’ or Acted in ‘Good Faith’: Sam Bankman-Fried’s Trial Opens

  • October 4, 2023
View Post
  • News

Google Pixel 8 Pro’s Best Take feature will fix your group photos, and I love it

  • October 4, 2023
View Post
  • News

Hackers exploit several security flaws in top Qualcomm GPUs

  • October 4, 2023
View Post
  • News

North Korean hackers are targeting aerospace – Lazarus Group tricks employees into installing malware themselves

  • October 4, 2023
View Post
  • News

Major Linux distros targeted by hackers exploiting this significant flaw

  • October 4, 2023
View Post
  • News

Black Friday electric scooter deals 2023: what we expect this year

  • October 4, 2023
View Post
  • News

Payday 3 is getting progression changes after all

  • October 4, 2023
View Post
  • News

Minecraft’s mob vote just got its first entry and perhaps much more

  • October 4, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.