Microsoft issued a warning about macOS security errors, urging users to update the software immediately
It is designed to prevent applications from accessing users' personal information without their prior knowledge and consent.
This is a high-risk-rated vulnerability that allows an attacker to remotely install spyware on a target's device. Therefore, users are recommended to update the operating system on their devices to the latest software version, in order to minimize any potential risks.
This vulnerability, called 'powerdir' (tracking identifier CVE-2021-30970), was first discovered by the Microsoft Security Vulnerability Research (MSVR) security team, and has been fully notified to Apple. through the Coordinated Vulnerability Disclosure (CVD) mechanism between major technology companies.
Talking about this vulnerability, the representative (MSVR) said:
'We discovered that it is possible to programmatically change the target user's home directory and create a dummy TCC database. This database stores the consent history of application requests. If exploited on unpatched systems, this vulnerability could allow an attacker to orchestrate an attack based on a user's protected personal data.
For example, an attacker could hijack an app installed on the device — or install their own malicious app — and gain access to the microphone to record private conversations, or capture screen shot of sensitive information displayed on the user's screen'.
Apple released a patch for the vulnerability on December 13, 2021. However, not many people are really aware of this issue. That's why Microsoft is urging macOS users to apply the patches as soon as possible.
You should read it
- Microsoft discovered a critical vulnerability on macOS
- Detecting a serious security vulnerability on macOS, this 18-year-old youth refused to disclose it because Apple did not pay the bonus
- Apple fixes many important bugs on MacOS X
- Mac computers stuck with a dangerous security vulnerability, Apple was announced in February but has not yet resolved
- Users need to update their iOS and Mac devices right away to avoid security vulnerabilities
- Microsoft fixes 28 Windows and Office security bugs
- Top 30 serious security holes are being exploited by hackers the most
- Apple patched a total of 43 security bugs for Mac OS X
May be interested
- The Gupteba botnet that infected 1 million Windows computers has just been taken down by Googleglopbeta is a dangerous type of malware with the ability to steal user information and cookies, mine virtual currency, deploy and operate proxy components... it usually targets both windows and device systems. iot devices.
- Dangerous malicious code, capable of self-mutating, attacking the vaccine manufacturing industrya dangerous type of malicious code, capable of mutating itself to avoid security software, is attacking vaccine manufacturing and supply companies globally.
- Detected malicious attack campaign targeting TikTok, threatening to delete accounts of many celebritiesinternational security researchers have recently issued an urgent warning about a new phishing attack campaign on the tiktok platform.
- AMD admits that its new driver update packages for Windows are becoming a 'shooting target' of hackersamd has just published a long list of security flaws and corresponding exploits related to their windows 10 graphics driver updates.
- What is a zero-click attack? How dangerous is it?the more the internet world develops, the more forms of cyber attacks are actively changing in a more complicated and dangerous direction.
- Hackers sell personal data of millions of people in Moscow for only $800an unidentified group of hackers is selling a package of stolen databases containing 50 million records of data related to transportation activities in moscow, russia.