Skip to main content

Google Project Zero reveals 'high severity' macOS vulnerability that Apple has failed to patch

  • March 4, 2019
  • 1 reply
  • 32 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
March 4, 2019, By Mark Wycislik-Wilson


Google's Project Zero has gone public about a "high severity" flaw in the macOS kernel after Apple failed to patch it 90 days after being told about the problem.

A security researcher discovered a problem in XNU that means it is possible to perform malicious activities. The security bug related to copy-on-write (COW) behavior, enabling an attacker to manipulate filesystem images without the operating system being notified. Apple was informed of the vulnerability back in November, but has failed to release a patch.

Writing about the vulnerability on the Chromium bug tracker -- highlighted by Neowin -- the security researcher explains: "XNU has various interfaces that permit creating copy-on-write copies of data between processes, including out-of-line message descriptors in mach messages. It is important that the copied memory is protected against later modifications by the source process; otherwise, the source process might be able to exploit double-reads in the destination process".

Full Article.

1 reply

NicCrockett
Popular Voice
Forum|alt.badge.img+28
  • Popular Voice
  • 300 replies
  • March 4, 2019
Apple have a flaw, never. You're just not holding the kernel right.

Reply