HomeLatest NewsCyber SecurityMicrosoft Mac apps vulnerability may have exposed users' cameras and microphones to hackers

Microsoft Mac apps vulnerability may have exposed users’ cameras and microphones to hackers

A vulnerability in Microsoft macOS apps potentially allowed unauthorised access to cameras and microphones. Despite updates to some apps, concerns remain over unresolved security risks in others.

Preferred Source of Google

A recently uncovered vulnerability in applications for macOS may have allowed unauthorised access to Mac users’ cameras and microphones, according to findings by cybersecurity researchers at Cisco Talos.

The flaw, which could be exploited through popular Microsoft apps like Outlook and Teams, underscores ongoing concerns about the security of widely used software.

Cisco Talos revealed that they had identified a vulnerability in several Microsoft apps for macOS that could have allowed attackers to gain access to a user’s camera and microphone without their knowledge.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Future-Ready Defence
Future-Ready Defence
A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.
Register Now →

The researchers detailed how the exploit works, explaining that involves the injection of malicious code into these applications, effectively hijacking the permissions the user had already granted to the app.

macOS, ‘s operating system, uses a framework known as Transparency, Consent, and Control (TCC) to manage permissions for access to sensitive resources like the camera, microphone, and location services.

Typically, an app needs specific entitlements to request such permissions, and without these entitlements, the app is unable to access these resources. However, the vulnerability identified by Cisco Talos allowed malicious software to take advantage of permissions that had already been granted to Microsoft apps.

Advertisement

The uncovered eight separate vulnerabilities across various Microsoft applications, which could enable attackers to bypass macOS’s permission model. This would allow them to use existing app permissions without any further user verification.

In practical terms, this means that a hacker could potentially develop software capable of recording audio or capturing photos without the user’s consent. Cisco Talos pointed out that all Microsoft apps, except for Excel, had the ability to record audio, and some could even access the camera.

Microsoft’s Response and Continuing Risks

Advertisement

Following the disclosure of these vulnerabilities, Microsoft classified the issue as “low risk,” citing the fact that the exploit relies on the loading of unsigned libraries, which are typically used to support third-party plugins.

In response, Microsoft has released updates for the macOS versions of Teams and OneNote to address how these applications handle library validation entitlements. However, other widely used apps, including Excel, PowerPoint, Word, and Outlook, remain potentially vulnerable.

Cisco Talos has raised concerns about Microsoft’s decision to disable certain security validations, particularly when there is no apparent need for additional libraries to be loaded. The researchers suggest that this could expose users to unnecessary risks.

The group also recommended that Apple consider making enhancements to the TCC framework to further protect users. One of their suggestions includes introducing user prompts when third-party plugins are loaded into apps that have already been granted permissions, which could mitigate the risk of similar vulnerabilities being exploited in the future.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
Advertisement
- Advertisement -
- Advertisement -

Cabinet Secretary directs ministries, states to comply with data protection law

Cabinet Secretary TV Somanathan has directed all central ministries and state governments to prepare compliance plans for the Digital Personal Data Protection Act, requiring data inventories, privacy reviews and senior officials to oversee implementation.

RELATED ARTICLES