Detecting a serious security vulnerability on macOS, this 18-year-old youth refused to disclose it because Apple did not pay the bonus
Linus Henze, an 18-year-old German, recently claimed to have discovered a serious security flaw on macOS that could expose the machine's storage passwords to malicious applications. Although this is only a bug on the Mac, if the Mac is linked to an iCloud account, this error may affect the synced password between the iPhone and the Mac.
It is worth mentioning that Linus Henze decided not to share details about this error on macOS because Apple will not pay bonuses for this type of discovery. This makes Apple unable to fix this vulnerability.
Linus Henze has discovered many different errors on iOS and macOS in the past. And according to Linus Henze, Apple doesn't pay for security vulnerabilities detection on macOS.
Henze said he discovered how to access the Mac's keychain system, which contained all of the user's private keys and passwords. If the bad guys take advantage of this vulnerability and gain important data, the user will be seriously affected.
Henze successfully installed malicious code in the form of a team application for Mac. This allowed him to read the code and password in the keychain system, even "walk around" in the Mark machine without the victim's permission.
There are many ways, both illegal and legal, to allow malicious code to enter the victim's computer. According to Henze's hypothesis, hackers could trick users into accessing a fake website, installing malicious code and stealing the token. From there, hackers can easily access their iCloud account, take up Apple ID and download the keychain from Apple's server.
Henze announced his findings just a week after teenager Grant Thompson, 14, found a security bug in the Group FaceTime feature and might be rewarded with $ 25-200 thousand by Apple.
Please follow Linus Henze's demo video about the keychain vulnerability on macOS.
You should read it
- How to scan websites for potential security vulnerabilities with Vega on Kali Linux
- Mac computers stuck with a dangerous security vulnerability, Apple was announced in February but has not yet resolved
- Google announced a serious vulnerability in the macOS kernel
- How to fix BlueKeep security error for Windows 2003, Windows XP, Windows 7, Windows Server 2008
- 6 enterprise security holes to note
- Microsoft introduced a tool to fix security holes in IE 9 and 10
- HP publishes a series of critical vulnerabilities in the Teradici PCoIP protocol
- 5 common errors in managing security vulnerabilities
May be interested
- AMD CPUs also have security vulnerabilities that have existed for many years now!another relatively serious vulnerability on amd processors has continued to be discovered, prompting the security community.
- Apple: Security flaw in iPhone's USB-C port is not a concernnew security vulnerability discovered on usb-c controller of iphone 15 and 16, should users worry?
- Mi 10 Youth Edition: Specifications and pricealong with miui 12, xiaomi has just launched the mi 10 youth edition 5g which has the same design and hardware configuration as the mi 10 lite but has an upgraded camera and has an impressive zoom of up to 50x.
- Mac computers stuck with a dangerous security vulnerability, Apple was announced in February but has not yet resolvedsecurity researcher filippo cavallarin discovered a security vulnerability on macos and informed apple from february 22, but to the latest macos version, 10.14.5, this vulnerability has not been fixed yet.
- Apple released a patch to fix security holes on Mac OS Xapple has just released the next update of mac os x, version 10.9.2, to address the security vulnerability it admitted a long time ago.
- 13 popular applications have serious security vulnerabilities, users need to update immediatelyapple and the citizen lab have just discovered a serious security vulnerability, affecting a series of popular applications and millions of internet users.
- Transfer money to Apple ID account, users will get 10% backaccording to information from macrumors, apple will reimburse users 10% of the total amount they transferred to their apple id account.
- Facebook launched a portal for young peopleyouth portal, youth portal, is a place for teenagers with dancing emoticons, social equality and blog posts. facebook's desire is that this portal will become a resource for young people so that they can have 'great experience' on facebook.
- Apple patched many zero-day bugs in iOS 15.4.1 and macOS 12.3.1 updatesapple has simultaneously released new versions of their software to update features, fix bugs and patch security holes.
- 7 Apple hacks, breaches, and security vulnerabilities you didn't know aboutapple is no stranger to security incidents, be they a hack, breach or security vulnerability. you may not be aware of these different problems, and some may still put you at risk.