Google Publicly Discloses macOS Kernel Vulnerability
#1
Exclamation 
Quote:After discovering security vulnerabilities in several Microsoft products, including Windows 10 itself, the Google Project Zero team returns with a new public disclosure, this time affecting Apple’s macOS.

Because as the security researchers working at Google discovered, a vulnerability in the macOS kernel allows an attacker to abuse the way filesystem images are mounted to make data changes.

In the technical analysis of the vulnerability, the Google Project Zero team explains that the way the copy-on-write feature is implemented in macOS makes it possible for a user to make changes to a mounted file system image without the operating system to be aware of them.

“If an attacker can mutate an on-disk file without informing the virtual management subsystem, this is a security bug. MacOS permits normal users to mount filesystem images. When a mounted filesystem image is mutated directly (e.g. by calling pwrite() on the filesystem image), this information is not propagated into the mounted filesystem,” the original advisory notes.

SOURCE: https://news.softpedia.com/news/google-p...5161.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • darktwilight
Reply


Messages In This Thread
Google Publicly Discloses macOS Kernel Vulnerability - by silversurfer - 04 March 19, 16:30

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Google Chrome 149.0.7827.200/201
Google Chrome 149....harlan4096 — 08:26
Brave 1.91.180 (Jun 26, 2026)
Release Notes v1.9...harlan4096 — 08:24
Adobe Acrobat Reader DC 2026.001.21691
Adobe Acrobat Read...harlan4096 — 08:22
PowerToys v0.100.2
Release v0.100.2 ...harlan4096 — 08:21
GeForce Game Ready Driver 452.06
NVIDIA 580.173.02 Li...harlan4096 — 08:18

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>