HomeSecurityMicrosoft reveals macOS vulnerability in Safari browser

Microsoft reveals macOS vulnerability in Safari browser

Microsoft has revealed details about a now-patched vulnerability in Apple 's Transparency, Consent, and Control (TCC) framework in macOS, which has likely been exploited to bypass privacy controls in Safari.

See also: Google Chrome: New API for fast translation of complex content

macOS Safari vulnerability

The vulnerability, codenamed HM Surf by the tech giant, is tracked as CVE-2024-44133. It was addressed by Apple as part of macOS Sequoia 15 by removing the vulnerable code.

The macOS vulnerability “ involves removing TCC protection for the Safari browser directory and modifying a configuration file in that directory to access data user , including browsing pages, the device’s camera, microphone, and location, without the user’s consent ,” Jonathan Bar Or of the Microsoft Threat Intelligence team said .

Microsoft said the new protections are limited to Apple's Safari browser and that it is working with other major browser vendors to further explore the benefits of hardening local configuration files.

HM Surf was discovered after other Apple macOS vulnerabilities such as Shrootless, powerdir, Achilles, and Migraine, which could allow malicious actors to bypass security enforcement actions.

See also: Apple: New public betas of iOS 18.1, iPadOS 18.1 and macOS Sequoia 15.1

While TCC is a security framework that prevents apps from accessing users ' personal information without their consent, the recently discovered bug could allow attackers to bypass this requirement and gain access to location services, address book, camera, microphone, downloads list, and more in an unauthorized manner.

Microsoft reveals macOS vulnerability in Safari browser
macOS vulnerability in Safari browser

Access is governed by a set of permissions, with Apple apps like Safari having the ability to bypass TCC entirely using the “com.apple.private.tcc.allow” permission.

While this allows Safari to freely access sensitive permissions, it also incorporates a new security mechanism called Hardened Runtime that makes it more difficult for arbitrary code to run within the web browser.

That said, when users visit a website that requests location or camera access for the first time, Safari requests access through a TCC-like pop-up window. These permissions are stored on a per-site basis in various files located in the “~/Library/Safari” directory.

See also: macOS Sequoia has caused problems for cybersecurity tools

The macOS operating system is known for security and reliability, but it is not invulnerable. Like any complex software, it can have vulnerabilities that can be exploited by malicious users. macOS vulnerabilities, such as the one affecting Safari, can come from outdated software versions, improperly updated applications, or incomplete security settings. Apple is constantly working to detect and fix these problems, regularly providing security updates to users. However, it is important for users to stay informed and practice good security practices, such as installing the latest updates and using protective software.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS