Microsoft issued a warning about macOS security errors, urging users to update the software immediately
It is designed to prevent applications from accessing users' personal information without their prior knowledge and consent.
This is a high-risk-rated vulnerability that allows an attacker to remotely install spyware on a target's device. Therefore, users are recommended to update the operating system on their devices to the latest software version, in order to minimize any potential risks.
This vulnerability, called 'powerdir' (tracking identifier CVE-2021-30970), was first discovered by the Microsoft Security Vulnerability Research (MSVR) security team, and has been fully notified to Apple. through the Coordinated Vulnerability Disclosure (CVD) mechanism between major technology companies.
Talking about this vulnerability, the representative (MSVR) said:
'We discovered that it is possible to programmatically change the target user's home directory and create a dummy TCC database. This database stores the consent history of application requests. If exploited on unpatched systems, this vulnerability could allow an attacker to orchestrate an attack based on a user's protected personal data.
For example, an attacker could hijack an app installed on the device — or install their own malicious app — and gain access to the microphone to record private conversations, or capture screen shot of sensitive information displayed on the user's screen'.
Apple released a patch for the vulnerability on December 13, 2021. However, not many people are really aware of this issue. That's why Microsoft is urging macOS users to apply the patches as soon as possible.
You should read it
- Apple expanded the size of the security bug detection program to receive bonuses, including macOS, a maximum bonus of $ 1 million
- Apple patched many zero-day bugs in iOS 15.4.1 and macOS 12.3.1 updates
- Microsoft discovered a critical vulnerability on macOS
- Detecting a serious security vulnerability on macOS, this 18-year-old youth refused to disclose it because Apple did not pay the bonus
- Apple fixes many important bugs on MacOS X
- Mac computers stuck with a dangerous security vulnerability, Apple was announced in February but has not yet resolved
- Users need to update their iOS and Mac devices right away to avoid security vulnerabilities
- Microsoft fixes 28 Windows and Office security bugs
- Top 30 serious security holes are being exploited by hackers the most
- Apple patched a total of 43 security bugs for Mac OS X
- Dynamics of Google, Apple and Microsoft when the browser has a security error
- Apple announced a new, more diverse level of security bug detection bonus
Maybe you are interested
There is a serious security vulnerability that has existed for 18 years in AMD processors, but it is not too worrying
A dangerous vulnerability that has existed for 18 years threatens millions of AMD Ryzen and EPYC CPUs
Google Workspace security vulnerability caused thousands of user accounts to be attacked
Thousands of iOS apps could be at risk because of an open source vulnerability
Serious vulnerability in OpenSSH threatens millions of servers
Google releases emergency update to patch Chrome vulnerability