HomeinetApple fixes Plug-n-Hack USB attack in MacOS

Apple fixes Plug-n-Hack USB attack in MacOS

Apple fixes Plug-n-Hack USB attack by releasing MacOS High Sierra 10.13.1, Sierra 10.12.6, and El Capitan 10.11.6 .

The Plug-n-Hack USB vulnerability concerns “fsck_msdos,” an Apple system tool that checks and fixes errors on storage devices with FAT filesystems. The tool runs automatically when a user connects a USB or SD card to a Mac.

Plug-n-Hack USB

The bug allows arbitrary code to run on your computer with system-level privileges, which results in a plug-n-play device (USB, SD Cards) having complete control of your computer.

Hackers exploit this by creating storage devices with various malwares that have the ability to run directly once connected to a computer, as “fsck_msdos” is a system utility and does not require user approval to execute.

As Trend Micro researcher Veo Zhang states, "All of this is caused by a very small bug in the program code that fails to increment the value of a variable and remains at the value -1, resulting in system memory corruption."

This bug has also been found in other code, specifically in Android code (CVE-2017-13811). The “fsck_msdos” utility appears in many NIX-based operating systems (Linux, Android, BSD Based Systems). Veo contacted the maintainers of these operating systems, but only Android engineers responded, emphasizing that this utility only runs in a strict SELinux domain, so it does not pose a risk to any user.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS