• Login
No Result
View All Result
My Blog
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    Listen to Music Without Blocking Out the World with These Headphones

    Listen to Music Without Blocking Out the World with These Headphones

    Air India To Use ‘Coruson’ Software For Safety Management

    Air India To Use ‘Coruson’ Software For Safety Management

    Bversity Raises INR 1.5 Crore In Seed Funding

    Bversity Raises INR 1.5 Crore In Seed Funding

    There’s So Much More to NFTs and Web3 Than the FTX Crash

    There’s So Much More to NFTs and Web3 Than the FTX Crash

    Why Software Talent Is Still in Demand Despite Tech Layoffs, Downturn and a Potential Recession

    Why Software Talent Is Still in Demand Despite Tech Layoffs, Downturn and a Potential Recession

    Are You Hesitant to Use AR Technology? Here’s Why You Need to Jump on It Now.

    Are You Hesitant to Use AR Technology? Here’s Why You Need to Jump on It Now.

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    Listen to Music Without Blocking Out the World with These Headphones

    Listen to Music Without Blocking Out the World with These Headphones

    Air India To Use ‘Coruson’ Software For Safety Management

    Air India To Use ‘Coruson’ Software For Safety Management

    Bversity Raises INR 1.5 Crore In Seed Funding

    Bversity Raises INR 1.5 Crore In Seed Funding

    There’s So Much More to NFTs and Web3 Than the FTX Crash

    There’s So Much More to NFTs and Web3 Than the FTX Crash

    Why Software Talent Is Still in Demand Despite Tech Layoffs, Downturn and a Potential Recession

    Why Software Talent Is Still in Demand Despite Tech Layoffs, Downturn and a Potential Recession

    Are You Hesitant to Use AR Technology? Here’s Why You Need to Jump on It Now.

    Are You Hesitant to Use AR Technology? Here’s Why You Need to Jump on It Now.

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
No Result
View All Result
My Blog
No Result
View All Result
Home Uncategorized

A Single Flaw Broke Every Layer of Security in MacOS

by lacygibson
August 13, 2022
in Uncategorized
0
A Single Flaw Broke Every Layer of Security in MacOS
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


every time you Shut down your Mac and a pop-up will appear: “Are you sure you want to shut down your computer now?” Below the prompt is another option that most of us probably overlook: reopen the applications you have now open when you turn the machine back on and window selection. Researchers have now found a way to exploit a vulnerability in this “saved state” feature — which could be used to compromise a key layer of Apple’s security protections.

Thijs Alkemade, a security researcher at Dutch cybersecurity firm Computest, said the vulnerability is vulnerable to a process injection attack to breach macOS security, potentially allowing an attacker to read every file on a Mac or control a webcam. defect. “It’s basically a vulnerability that can be applied in three different places,” he said.

After deploying an initial attack on the save-state feature, Alkemade was able to traverse the rest of the Apple ecosystem: first escape the macOS sandbox, which was designed to confine successful hacks to one app, and then bypass the system integrity Security Protection (SIP ), a key defense designed to block authorization codes from accessing sensitive files on your Mac.

Alkemade, who presented the work at the Black Hat conference in Las Vegas this week, first discovered the vulnerability in December 2020 and reported the issue to Apple through its bug bounty program. He said he was paid “pretty well” for the research, although he declined to elaborate on the exact amount. Apple has since released two updates to fix the vulnerability, the first in April 2021 and the second in October 2021.

When asked about the flaw, Apple said it had no comment prior to the Alkemade demo. The company’s two public updates on the vulnerability did not elaborate, but they said the issues could allow malicious apps to leak sensitive user information and elevate an attacker’s privileges to move around the system.

A blog post describing the Alkemade attack said Apple’s changes could also be seen in Xcode, the company’s development workspace for app creators. While Apple has fixed issues with Macs running the Monterey operating system released in October 2021, previous macOS versions are still vulnerable, the researchers said.

There are multiple steps to a successful attack, but fundamentally they go back to the original process injection vulnerability. Process injection attacks allow hackers to inject code into a device and run the code differently than originally intended.

Attacks are not uncommon. “Often process injection vulnerabilities can be found in specific applications,” Alkemade said. “But it’s very rare to have such a general finding,” he said.

The vulnerability discovered by Alkemade is in a “serialized” object in the saved state system, which saves the applications and windows you have open when you shut down your Mac. This saved state system can also run while the Mac is in use, in a process called App Nap.



Source link

lacygibson

lacygibson

Next Post
A Single Flaw Broke Every Layer of Security in MacOS

A Single Flaw Broke Every Layer of Security in MacOS

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

J Aach — OfficialUSA.com Records

7 months ago
One Phone to Rule Them All—Apple Unleashes the iPhone 14 Pro

One Phone to Rule Them All—Apple Unleashes the iPhone 14 Pro

5 months ago

Popular News

    Connect with us

    • Contact
    • Read Latest News Around The World – Frapios
    Write Us at: [email protected]

    Copyright Reserved © 2022

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    Copyright Reserved © 2022

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In