HomeLatest NewsCyber SecuritymacOS Mojave: Researcher claims to have found new vulnerability

macOS Mojave: Researcher claims to have found new vulnerability

Preferred Source of Google

A researcher has claimed to have found a new vulnerability in the latest version of macOS Mojave that too just a few hours before the software was scheduled to be released. The researcher had tweeted a video on Monday that showed the bypass of a security feature that’s designed to prevent apps from improperly accessing a user’s personal data.

According to the video that was posted on Twitter by Patrick Wardle, chief researcher officer at Digita Security, can be seen that the macOS initially refused access to the stored contacts saying that the “operation was not permitted”. But when the researcher executed an unprivileged script simulating a malicious app, it copied his entire address book to the thus bypassing the security feature.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Future-Ready Defence
Future-Ready Defence
A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.
Register Now →

However, the bypass does not work with all of the new privacy protection features and hardware-based components such as the webcam are not affected. The entire description of the vulnerability is not available yet, as the plan to share technical details in November at a conference.

Wardle told TechCrunch that his findings are “not a universal bypass” of the feature, but that the bug could allow a malicious app to grab certain protected data, such as a user’s contacts, when a user is logged in.

“The security researcher has just shared a POC (Proof of Concept) and no specific details of how the vulnerability is exploited have been made public. This means that most hackers whether malicious or non-malicious won’t get their hands on how the researcher managed to do it until they get encouraged enough and find it out on their own which is bound to take a good amount of time,” said Ankush Johar, Director at Infosec Ventures.

Advertisement

As the researcher has said that he would be presenting the vulnerability in a conference it is extremely probable that he will be reporting the bug to Apple and make sure Apple patches it before he presents it as this is the general expected flow after finding a zero-day and going public with it.

It’s completely obvious that Apple does a rigorous amount of security testing before releasing an update but this incident just goes on to show the power of crowd-sourced security, said Johar.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

M Kalam
M Kalam
M Kalam covers technology and e-goverance for TechObserver.in.
Advertisement
- Advertisement -
- Advertisement -

Cabinet Secretary directs ministries, states to comply with data protection law

Cabinet Secretary TV Somanathan has directed all central ministries and state governments to prepare compliance plans for the Digital Personal Data Protection Act, requiring data inventories, privacy reviews and senior officials to oversee implementation.

RELATED ARTICLES