macOS 11.3 patches bug that allowed attacks to bypass Mac security

Posted:
in General Discussion
Apple in macOS Big Sur 11.3 fixed a bug that could have allowed attackers to bypass the Mac's security mechanisms with a malicious document.

Credit: AppleInsider
Credit: AppleInsider


The software flaw allowed attackers to create a malicious application that could masquerade as a document, TechCrunch reported Monday. Security researcher Cedric Owens first discovered the bug in March.

According to Owens, "all the user would need to do is double click -- and no macOS prompts or warnings are generated." The researcher created a proof-of-concept app that exploited the flaw to launch the Calculator app.

Although Owens' demonstration app was harmless, a malicious attacker could have leveraged the vulnerability to remotely access sensitive data or other information on a user's machine by tricking them into clicking a spoofed document.

Security researcher and Mac specialist Patrick Wardle also reported that the bug is being actively exploited in the wild as a zero-day vulnerability. He added that the flaw was caused by a logic issue in macOS's code.

Apple told TechCrunch that it patched the bug in macOS Big Sur 11.3, which the Cupertino tech giant released on Monday. In addition to that release, Apple also issued patches for the flaw to macOS Catalina and macOS Mojave.

In addition to patching the specific vulnerability, Apple's macOS Big Sur 11.3 update also includes fixes for a bevy of other security flaws.

macOS Big Sur 11.3 should now be available as an over-the-air update to all users on compatible Macs.

Comments

  • Reply 1 of 4
    lkrupplkrupp Posts: 10,557member
    Security updates for Mojave and Catalina also released patching the same issues.
    watto_cobra
  • Reply 2 of 4
    Does anyone know if YouTube is compatible with M1? I know this article is not about that. The article I was trying to post in had the thread discontinued. 
    watto_cobra
  • Reply 3 of 4
    nicholfdnicholfd Posts: 824member
    Does anyone know if YouTube is compatible with M1? I know this article is not about that. The article I was trying to post in had the thread discontinued. 
    Youtube web site works just fine on an M1.  Who needs an app for YouTube?
    watto_cobra
  • Reply 4 of 4
    Rayz2016Rayz2016 Posts: 6,957member
    lkrupp said:
    Security updates for Mojave and Catalina also released patching the same issues.
    But … but … built-in obselence!
    watto_cobra
Sign In or Register to comment.