Tag: macOS Vulnerability

Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation
News

Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation

A now-patched security flaw in Apple macOS has been made public by Microsoft. If it had been successfully exploited, it could have enabled an attacker operating as "root" to get around System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions. The medium-severity issue, CVE-2024-44243 (CVSS score: 5.5), was fixed by Apple in macOS Sequoia 15.2, which was made available last month. According to the iPhone manufacturer, it's a "configuration issue" that could allow a malicious program to alter file system components that are secured. The Microsoft Threat Intelligence team's Jonathan Bar Or stated that circumventing SIP could have detrimental effects, including making it more likely for attackers and malware developers to install ro...
Microsoft Reveals macOS Vulnerability that Bypasses Privacy Controls in Safari Browser
News

Microsoft Reveals macOS Vulnerability that Bypasses Privacy Controls in Safari Browser

Microsoft has made information regarding a security vulnerability that has been fixed in Apple's Transparency, Consent, and Control (TCC) framework for macOS public. This vulnerability has probably been used to circumvent users' privacy settings and obtain data. The tech giant dubbed the vulnerability HM Surf, and it is recorded as CVE-2024-44133. Apple removed the vulnerable code as part of macOS Sequoia 15 to resolve it. According to Jonathan Bar-Or of the Microsoft Threat Intelligence team, HM Surf entails deleting the TCC protection for the Safari browser directory and altering a configuration file in that directory to obtain access to the user's data, including pages visited read more about Microsoft Reveals macOS Vulnerability that Bypasses Privacy Controls in Safari Browser. ...