Microsoft Details macOS Bug That Could Let Attackers Gain Access to User Data
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-27937 | A logic issue was addressed with improved state management. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to access private information. NVD description · AI analysis pending | 5.5 | 1% |
| — | ||
| CVE-2020-9934 | Environment Variable Handling Information Disclosure in Apple iOS, iPadOS, and macOS CVE-2020-9934 is an input validation flaw in the way Apple operating systems handled environment variables, which could allow a local user to view sensitive user information. It is triggered by a local attacker or user with limited privileges running code or commands on a vulnerable device, where the mishandled environment variables leak data. Successful exploitation results in disclosure of confidential information only, with no impact on data integrity or availability per the CVSS scoring. It affects devices running iOS or iPadOS versions before 13.6 and macOS Catalina versions before 10.15.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08, confirming exploitation in the wild, though no public proof-of-concept is known. Do: Upgrade affected devices to iOS 13.6 / iPadOS 13.6 or later, and macOS Catalina systems to 10.15.6 or later, as required by CISA's KEV listing. Because exploitation requires local access, restrict local user accounts on shared Macs and iOS devices and review who can execute code on them. Use MDM or endpoint inventory to confirm fleet-wide patch levels against these minimum versions. | 5.5 | 3% | KEV |
| masshundreds of millions of devices (Apple's active iOS/macOS install base exceeds 1 billion, and all devices on pre-fix builds at disclosure were affected) | |
| CVE-2021-30713 | Privacy Preferences (TCC) Bypass in Apple macOS, Actively Exploited CVE-2021-30713 is a permissions/authorization flaw (CWE-862) in Apple macOS that allows a malicious application already running on a machine to bypass the user's Privacy preferences, which govern which apps may access protected user data such as files, camera, microphone, and other consent-protected resources. The flaw is triggered locally: a malicious app that a user has launched can silently circumvent the Privacy controls without the usual approval prompt. Successful exploitation grants the attacker access to user data that should have required explicit user consent, with high impact to confidentiality, integrity, and availability per its 7.8 CVSS score. Any Mac running a version of macOS prior to the macOS Big Sur 11.4 fix is affected. Apple acknowledged a report that the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; the EPSS score of 7.0% (94th percentile) further indicates meaningful near-term exploitation risk. Do: Upgrade affected Macs to macOS Big Sur 11.4 or later immediately, as this issue is listed in CISA's KEV catalog with active exploitation confirmed. Audit Macs for unknown or recently installed applications that accessed protected data (files, camera, microphone) without a consent prompt, and prioritize internet-facing and high-value endpoints. Since Apple shipped this fix alongside other actively exploited zero-days in the same release cycle, ensure devices are fully updated rather than partially patched. | 7.8 | 7% | KEV |
| masstens of millions of Macs (macOS runs on an installed base estimated at 100M+ devices, and Big Sur was the current release when the patch shipped) | |
| CVE-2021-30970 | A logic issue was addressed with improved state management. A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, macOS Big Sur 11.6.2. A malicious application may be able to bypass Privacy preferences. NVD description · AI analysis pending | 5.5 | 15% |
| — |
Full article435 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 11, 2022
Microsoft on Monday disclosed details of a recently patched security vulnerability in Apple's macOS operating system that could be weaponized by a threat actor to expose users' personal information.
Tracked as CVE-2021-30970, the flaw concerns a logic issue in the Transparency, Consent and Control (TCC) security framework, which enables users to configure the privacy settings of their apps and provide access to protected files and app data. The Security & Privacy pane in the macOS System Preferences app serves as the front end of TCC.
Microsoft 365 Defender Research Team, which reported the vulnerability to Apple on July 15, 2021, dubbed the flaw "powerdir." Apple addressed the issue as part of macOS 11.6 and 12.1 updates released in December 2021 with improved state management.
While Apple does enforce a policy that limits access to TCC to only apps with full disk access, it's possible to orchestrate an attack wherein a malicious application could work around its privacy preferences to retrieve sensitive information from the machine, potentially allowing an adversary to access microphone to record private conversations or capture screenshots of sensitive information displayed on the user's screen.
"We discovered that it is possible to programmatically change a target user's home directory and plant a fake TCC database, which stores the consent history of app requests," Jonathan Bar Or of Microsoft 365 Defender Research Team said. "If exploited on unpatched systems, this vulnerability could allow a malicious actor to potentially orchestrate an attack based on the user’s protected personal data."
In other words, if a bad actor gains full disk access to the TCC databases, the intruder could edit it to grant arbitrary permissions to any app of their choice, including their own, effectively permitting the app run with configurations previously not consented to.
CVE-2021-30970 is also the third TCC-related bypass vulnerability to be discovered after CVE-2020-9934 and CVE-2020-27937, both of which have since been remediated by Apple. Then in May 2021, the company also patched a then zero-day flaw in the same component (CVE-2021-30713) that could allow an attacker to gain full disk access, screen recording, or other permissions without users' explicit consent.
"This shows that even as macOS or other operating systems and applications become more hardened with each release, software vendors like Apple, security researchers, and the larger security community, need to continuously work together to identify and fix vulnerabilities before attackers can take advantage of them," Bar Or said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/01/microsoft-details-macos-bug-that-could.html