Technology

#Hackers Have Already Bypassed Apple’s Emergency macOS Security Fix – Review Geek

“#Hackers Have Already Bypassed Apple’s Emergency macOS Security Fix – Review Geek”

The MacBook Pro on a red and blue background.
Apple

Apple recently patched a critical macOS vulnerability that lets hackers run arbitrary code through email attachments. Unfortunately, this patch is sloppy and extremely easy to bypass. Mac owners should avoid opening email attachments with the inetloc extension until Apple issues a proper fix.

Internet shortcut files, called inetloc files on macOS, are meant to redirect users to webpages. You can create an inetloc file by dragging a URL to your desktop, for example. But because of a bug in macOS, hackers can embed usable code within inetloc files. This code runs without warning when an affected file is opened, providing an easy way to attack macOS users via email.

Programming the exploit requires little computing experience. See, inetloc files contain URLs, which usually begin with http:// or https://. But an oversight by Apple lets inetloc files point to file:// locations within your computer system. A small line of code within an inetloc file could let a hacker run software or malicious payloads on your system.

Researcher Park Minchan discovered the exploit early this week. Apple quickly issued a patch after the vulnerability was reported by SSD Secure Disclosure, though several tech outlets and security experts find that this patch isn’t enough.

As reported by Ars Technica, the emergency patch issued by Apple prevents macOS from running inetloc files that begin with a file:// prefix. But the patch is case-sensitive. Replacing any part of file:// with a capital letter completely bypasses the fix.

This is amateurish work from Apple. It’s the kind of fix you’d expect from an intern at a small company. And frankly, it’s a worrying sign that Apple doesn’t take security as seriously as it claims. I guess that’s why we haven’t seen the “what happens on your iPhone stays on your iPhone” billboard in a while.

Source: Ars Technica, Apple Insider

If you liked the article, do not forget to share it with your friends. Follow us on Google News too, click on the star and choose us from your favorites.

For forums sites go to Forum.BuradaBiliyorum.Com

If you want to read more like this article, you can visit our Technology category.

Source

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Close

Please allow ads on our site

Please consider supporting us by disabling your ad blocker!