Information has surfaced regarding a security flaw in Apple’s iOS and macOS that has been patched. If exploited successfully, the flaw might circumvent the Transparency, Consent, and Control (TCC) framework and allow unwanted access to private data.
According to Apple, the vulnerability, identified as CVE-2024-44131 (CVSS score: 5.3), affects the FileProvider component. Updates to iOS 18, iPadOS 18, and macOS Sequoia 15 have improved the validation of symbolic links, or “symlinks.”
According to Jamf Threat Labs, which found and disclosed the vulnerability, a rogue installed on the system may utilize the TCC bypass to steal confidential information without the users’ awareness read more about Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
