Skip to main content

Attackers exploit a macOS Catalina bug that had been fixed in Big Sur months before


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Big Sur got a fix 234 days before Catalina did, although both are supported.

 

ANDREW CUNNINGHAM - 11/12/2021

 

News is making the rounds today, both via a write-up in Vice and a post from Google's Threat Analysis Group, of a privilege escalation bug in macOS Catalina that was being used by "a well-resourced" and "likely state-backed" group to target visitors to pro-democracy websites in Hong Kong. According to Google's Erye Hernandez, the vulnerability (labeled CVE-2021-30869) was reported to Apple in late August of 2021 and patched in macOS Catalina security update 2021-006 on September 23. Both of those posts have more information on the implications of this exploit—it hasn't been confirmed, but it certainly appears to be yet another front in China's effort to crack down on civil liberties in Hong Kong—but for our purposes, let's focus on how Apple keeps its operating systems up to date, because it has even wider implications.

 

>> Full Article <<

0 replies

Be the first to reply!

Reply