Gatekeeper, the system used by macOS to authenticate applications, has a vulnerability. Without a warning, malware may have been injected. Here are the explanations.

On macOS, a fresh serious security hole has been the subject of a new discovery. Microsoft cybersecurity researcher Jonathan Bar Or was able to identify this problem. The specifics of this new vulnerability are covered in a blog post by Microsoft Security Threat Intelligence that was posted on Monday, December 19.

Microsoft discovers a security flaw in macOS

The CVE-2022-42821 flaw, which they call “Achilles” since July 27, 2022, enables getting around Apple’s Gatekeeper protection. Software downloaded from the internet can be verified thanks to a program created by the Apple company.

According to a statement by Apple on its website, “when you install Mac programs, add-ons, and installers that aren’t from the App Store, macOS validates the developer’s ID signature to make sure the product is from an identified source and hasn’t got modifications”. Thus, the user is secure against the download of viruses and other harmful software.

Jonathan Bar Or demonstrate the recently found weakness via a PoC, or Proof of Concept (prototype). He was able to create a program that prevents a file from adding to the ACL (Access Control List). The browser downloaded program was no longer marked as “unverified,” and it could subsequently be installed without encountering any problems.

By using this method, hackers might be able to spread malware. Without Gatekeeper being able to determine where it came from and who developed it.

apple, news, microsoft

An update is already available

The Apple teams were aware of the problem at that time. A rapid security update was available. The bug got a fix on December 13th in macOS 13 (Ventura), macOS 12.6.2 (Monterey), and macOS 1.7.2 (Big Sur). According to our colleagues at BleepingComputer.

So, this kind of zero day flaw will not be a problem. By the Lockdown mode that Apple created and included in macOS Ventura. However, according to researchers at Microsoft Security Threat Intelligence, the computer is not immune to the “Achilles” flaw. Regardless of the activation status of Lockdown Mode, the experts advise end users to apply the patch. Apple claims that it has fixed the problem by doing better checks.

macOS vulnerabilities by year

Gizchina News of the week



Vulnerabilities By Year
5 20 26 54 97 105 103 97 84 99 79 40 69 132 407 218 308 110 308 314 332 93  2001 5  2002 20  2003 26  2004 54  2005 97  2006 105  2007 103  2008 97  2009 84  2010 99  2011 79  2012 40  2013 69  2014 132  2015 407  2016 218  2017 308  2018 110  2019 308  2020 314  2021 332
 2022 93

Source/VIA :

BleepingComputer

TECH NEWS RELATED

New study says light pollution is making it harder to see the stars

Being able to watch cosmic events and take in the full breadth of the universe’s stars from the comfort of your backyard is one of the oldest joys skywatchers have to hold onto. However, a new study says skyglow is becoming too bright and light pollution is hiding the stars. ...

View more: New study says light pollution is making it harder to see the stars

Age of Wonders 4 will reach consoles in May

The Age of Wonders is back! Nine years after the classic Age of Wonders 3, and four after Planetfall’s spinoff, Age of Wonders 4 was announced for consoles and PC. The new game will reach these platforms on May 2, allowing players to relive the tactical adventure. To those ...

View more: Age of Wonders 4 will reach consoles in May

Don't worry, Quordle is not going behind a paywall, says Merriam-Webster

The four-way Wordle competitor has a new owner and will stay free

View more: Don't worry, Quordle is not going behind a paywall, says Merriam-Webster

AYA NEO Pocket Air is an Android gaming handheld with OLED display

Android is now fully ready to be utilized in a gaming handheld console. We have already seen a couple of new Android handhelds from big companies last year. And now more companies are launching their handhelds. The one we are talking about today is the AYA NEO Pocket Air. This ...

View more: AYA NEO Pocket Air is an Android gaming handheld with OLED display

Jaguars vs Chiefs live stream: how to watch the NFL playoff game online

(Image: © Getty Images / David Eulitt) Swipe to scroll horizontally Jaguars vs Chiefs live stream Kick-off: Saturday, January 21, 4.30pm ET / 1.30pm PT / 9.30pm GMT TV channel: NBC Live stream: Peacock TV (US) | DAZN (CA) | Sky (UK) | 7Plus (AU) Use ExpressVPN to watch ...

View more: Jaguars vs Chiefs live stream: how to watch the NFL playoff game online

Word can’t do this because a dialog box is open

Microsoft Word is the best word editor available for users. While it is almost perfect, many users report a problem with the application where they encounter the error Word can’t do this because a dialog box is open. The error occurs while creating a new Word document or opening an ...

View more: Word can’t do this because a dialog box is open

A Twisted New Body Dysmorphia Romantic Film Looks Gruesomely Unique

Some movie trailers do their best to push all the information you might need before the premiere to let you properly gauge your interest. Other trailers don’t care about all that and only want to show you a series of odd sequences you cannot piece together, but know you’ll ...

View more: A Twisted New Body Dysmorphia Romantic Film Looks Gruesomely Unique

How to Disable Screenshot Thumbnail Previews on Mac

Modern versions of macOS feature a floating thumbnail preview for screenshots that allows users to quickly apply edits to their screenshots before they save them. If you find this interface too obtrusive, or simply prefer to edit your screenshots later using the Preview app, Here is how you can ...

View more: How to Disable Screenshot Thumbnail Previews on Mac

LG’s smart projector is the square cousin of Samsung’s cool The Freestyle

Instagram admits it is showing people way too many videos

This Tiny MSI PC is Packed With Power

Siri accidentally sends 15 police officers to Muay Thai trainer’s gym

Logitech’s New Colorful Keyboards and Mice Look Great

15 Fixes: Cannot Verify Server Identity Errors for Apple Devices

10 Best Solutions To Fix DNS Errors In Windows

[7 Fixes] Windows Photos App Slow To Open Issue In Windows

“Part of the Journey Is the End;” Marvel’s Avengers Seems to be Shutting Down

How To Find Your Laptop IP Address

8 Fixes: Microsoft Windows Security Not Opening

9 Best Ways To Retrieve A Downloaded Movie On Your Laptop

OTHER TECH NEWS

Top Car News Car News