HomeSecurityMacKeeper fixes critical security hole

MacKeeper fixes critical security hole

MacKeeper

The developers of MacKeeper, the controversial OS X, have patched a critical vulnerability that could be exploited to remotely execute arbitrary code on an affected system.

The existence of the vulnerability was reported last week by security Braden Thomas, who published a proof-of- concept (PoC)to demonstrate his finding.

The security hole was created due to the way MacKeeper handles custom URLs , as SecureMac reports in an advisory.

An attacker can remotely exploit the hole to execute arbitrary code, if they can trick the victim and cause them to visit a specially crafted website.

If the user is already logged in, when they click on the malicious link, the attacker's code will be executed with administrator privileges. If the victim is not logged in, they will be prompted to enter their username and password. However, SecureMacpoints out that the text in the authentication dialog box may be controlled by the attacker, increasing the chances of a successful attack.

[blockquote]"This hole appears to result from MacKeeper's lack of input validation when executing commands using a custom URL system,"
SecureMac reports.

" Apple 's inter-application programming guide explicitly tells developers to validate the input they receive from these custom URLs to avoid issues with their handling. Additionally, as SecureMac points out , Apple provided information about the necessity of input validation in its ' Secure Coding Guide . ' "

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS