Mac Mojave Zero-Day Allows Malicious Apps to Access Sensitive Info
#1
Quote:A zero-day vulnerability in the brand-new version of the Apple Mojave macOS has been uncovered, which would allow an attacker to access private and confidential information by using an unprivileged app.

The flaw was uncovered by Patrick Wardle, co-founder of Digita Security and creator of Objective-See Mac security tools. On Monday, Wardle announced on Twitter that: “Mojave’s ‘dark mode’ is gorgeous…but its promises about improved privacy protections? kinda #FakeNews.”

Mac Mojave 10.14, released on Monday, contains security fixes for several issues, and introduces new user data protections. These require explicit consent by users for apps to access sensitive areas like location services, contacts, calendars, reminders, photos and so on. It’s a measure meant to thwart malicious actors looking to use synthetic clicks to simulate human finger touches and gain access to private information. Now, authorization prompts pop up that require direct, real user interaction before an app can tap sensitive information. However, users can whitelist (i.e., preauthorize) trusted apps.

Source: https://threatpost.com/mac-mojave-zero-d...fo/137674/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Publishes Firefox Roadmap With N...
Mozilla has releas...harlan4096 — 10:18
Sysinternals Suite 6.17.2026
Sysinternals Suite ...harlan4096 — 10:00
AxCrypt 3.1.1.0
AxCrypt 3.1.1.0: ...harlan4096 — 09:57
Tor Browser 15.0.16
Tor Browser 15.0.1...harlan4096 — 09:56
Bitdefender 27.0.60.338
Latest version of ...harlan4096 — 09:54

[-]
Birthdays
Today's Birthdays
avatar (39)biobdam
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>