ZeroHour
The Recordpublished ()ingested

Apple fixes macOS zero

criticalExploit / PoCimportance 60CVE-2021-30713

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30713
Privacy Preferences (TCC) Bypass in Apple macOS, Actively Exploited

CVE-2021-30713 is a permissions/authorization flaw (CWE-862) in Apple macOS that allows a malicious application already running on a machine to bypass the user's Privacy preferences, which govern which apps may access protected user data such as files, camera, microphone, and other consent-protected resources. The flaw is triggered locally: a malicious app that a user has launched can silently circumvent the Privacy controls without the usual approval prompt. Successful exploitation grants the attacker access to user data that should have required explicit user consent, with high impact to confidentiality, integrity, and availability per its 7.8 CVSS score. Any Mac running a version of macOS prior to the macOS Big Sur 11.4 fix is affected. Apple acknowledged a report that the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; the EPSS score of 7.0% (94th percentile) further indicates meaningful near-term exploitation risk.

Do: Upgrade affected Macs to macOS Big Sur 11.4 or later immediately, as this issue is listed in CISA's KEV catalog with active exploitation confirmed. Audit Macs for unknown or recently installed applications that accessed protected data (files, camera, microphone) without a consent prompt, and prioritize internet-facing and high-value endpoints. Since Apple shipped this fix alongside other actively exploited zero-days in the same release cycle, ensure devices are fully updated rather than partially patched.

7.87% KEV
  • Apple macOS (Big Sur) prior to 11.4
  • Apple macOS / Mac OS X (per CISA CPE)
masstens of millions of Macs (macOS runs on an installed base estimated at 100M+ devices, and Big Sur was the current release when the patch shipped)
Full article427 words · extracted from therecord.media · click to collapse

Apple has released today security updates for several of its products, including a patch for its macOS desktop operating system that includes a fix for a zero-day vulnerability that has been abused in the wild for almost a year by the XCSSET malware gang.

Tracked as CVE-2021-30713, the zero-day was discovered by researchers at security firm Jamf during an analysis of XCSSET, a malware strain that was spotted in the wild in August 2020, hidden inside malicious Xcode projects hosted on GitHub.

"Upon initial discovery, one of the most notable features of the XCSSET malware was that it reportedly utilized two zero-day exploits," Jamf said in a blog post today.

"[The] first was used to steal the Safari browser cookies [...]; while the second was used to bypass prompts in order to install a developer version of the Safari application."

Third XCSSET zero-day was used to bypass macOS TCC

But Jamf researchers said they found a third zero-day in the XCSSET malware source code during an analysis of this older threat, which has been recently updated to attack M1-based macOS systems.

Packed as an AppleScript, this zero-day allowed the malware to bypass Transparency Consent and Control, which is the macOS service that shows permissions popups every time an app wants to perform an intrusive action, such as using the camera, the microphone, or recording the user's screen and key presses.

According to the Jamf crew, the XCSSET malware gang abused CVE-2021-30713 in order to search macOS for the IDs of other apps that received a dangerous permission and would later plant a malicious applet inside one of these legitimate apps to perform malicious actions, such as taking a screenshot of the victim's desktop.

Following Jamf's report, Apple has patched TCC today in a security update for macOS Big Sur 11.4.

Apple users still running older versions of macOS are vulnerable to attacks and are advised to update their systems.

While the XCSSET malware and its distribution campaign is generally a very niche attack targeted mainly at developers, there is also the danger that other malware gangs will utilize the information shared by Jamf today to update their code and abuse CVE-2021-30713 for their attacks as well—hence why macOS users are advised to update to the latest macOS Big Sur 11.4.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/apple-fixes-macos-zero-day-abused-by-xcsset-malware