Microsoft discovered a critical vulnerability on macOS
An attacker could exploit this Shrootless vulnerability to bypass Apple's System Integrity Protection (SIP) and perform arbitrary actions, elevating privileges to root and install rootkits. on the victim's devices.
After discovering the vulnerability, the Microsoft 365 Defender Research Team security research team reported it to Apple through the Microsoft Security Vulnerability Research (MSVR) program. The vulnerability has also been assigned the CVE code as CVE-2021-30892 for easy tracking.
SIP (also known as rootless) is a macOS security technology that helps prevent malware from tampering with protected folders and files. SIP works by restricting the root user account and limiting the actions it can perform on protected parts of the operating system.
By design, SIP only allows programs that have been certified by Apple or those with special permissions (Apple software updates and Apple installers) to interfere with, modify, protection of macOS.
Microsoft researchers discovered Shrootless after noticing that the system-installd daemon had the com.apple.rootless.install.inheritable permission that allowed any subprocess to bypass the limitations of the SIP system .
According to Microsoft experts, after bypassing SIP, an attacker can install rootkits on the machine, overwrite system files or install malicious code without being detected.
Apple released a patch for the Shrootless vulnerability on October 26. Microsoft experts highly appreciate Apple's professionalism and quickness in handling this security hole.
You should read it
- Google announced a serious vulnerability in the macOS kernel
- Hackers can modify Safari on macOS to steal user data
- Users need to update their iOS and Mac devices right away to avoid security vulnerabilities
- Vulnerability on macOS helps hackers easily overcome security barriers
- Detecting vulnerabilities in iOS 12 and macOS caused device crash
- Microsoft issued a warning about macOS security errors, urging users to update the software immediately
- Apple expanded the size of the security bug detection program to receive bonuses, including macOS, a maximum bonus of $ 1 million
- Apple updated the password revealing patch from the Disk Utility function
May be interested
- Why did Facebook change its name to META?facebook changed its name to meta, a lot of you are misunderstanding the problem. why did facebook change its name to meta? what are their ambitions?
- Microsoft is forcing Windows 10 users to install the PC Health Check appthe pc health check application will be silently installed automatically during the application of update kb5005463.
- Apple confirms the existence of a series of serious vulnerabilities that can cause iPhones to be hackedapple has released patches for 22 security holes, including some serious vulnerabilities that can make iphones vulnerable. this notice was posted by apple on its support website.
- KDE Connect is officially available on iPhonekde connect is a cross-platform application developed by kde itself that supports wireless communication and data transfer between devices over a local area network.
- Microsoft is developing a low-cost Surface computer running Windows 11 SEmicrosoft's microsoft surface hardware product line was launched in 2012 and so far there have been quite a few devices with different forms. we can mention impressive products such as surface pro, surface go, surface laptop, surface laptop studio, surface hub, surface duo...
- Microsoft begins to impose a 'expiry date' for Windows updatesmicrosoft has now started removing old, outdated quality updates from windows update servers. these deleted updates will be labeled as 'expired updates'.