Google Project Zero Reveals 'High Severity' macOS Flaw

Advertisement
By Gadgets 360 Staff | Updated: 6 March 2019 09:58 IST
Highlights
  • Apple is yet to release a fix for the disclosed vulnerability
  • The company is said to be working on a patch, but there is no timeline
  • The flaw disclosed by Google Project Zero is said to be hard to exploit

Google Project Zero team had revealed the flaw to Apple on November 30, 2018

Google's Project Zero team has revealed a “high severity” macOS kernel flaw that allows an attacker to modify a user-owned mounted filesystem without the knowledge of macOS memory manager. Even after getting information about the flaw on November 30, 2018, Apple is yet to release a patch for the same, leaving macOS users vulnerable to possible exploitation. Project Zero team has a strict automatic 90-days disclosure policy, which means even if a company has not released a fix 90 days after being informed by Google, the team will publicly reveal the security vulnerability. The team does offer a grace period in select cases but that hasn't happened with Apple in this instance. 

The Project Zero team writes that they found a loophole in the copy-on-write (CoW) protection of macOS, which manages the computer's memory and makes sure that a process doesn't change the data shared by other processes. The team discovered that when a mounted filesystem image is changed directly, macOS doesn't propagate the information to its memory manager. So basically, an attacker can unmount a file system and then remount it with changed data and the system would be none wiser.

The Wired notes that it will be really hard to exploit the flaw disclosed by Project Zero and it needs the prospective victim to already have some kind of malware present on their computer.

Advertisement

Apple is yet to publicly comment on the security flaw, but it is said to be working on patch, which will arrive with a future release.

Advertisement

"We've been in contact with Apple regarding this issue, and at this point no fix is available," the researchers told ZDNet in a statement. "Apple are intending to resolve this issue in a future release, and we're working together to assess the options for a patch."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Raktabeej 2 Arrives on OTT Platforms This November: All You Need to Know
  1. Goodbye June OTT Release Date Revealed: When, Where to Watch Kate Winslet, Helen Mirren-Starrer Online
  2. Raktabeej 2 Arrives on OTT Platforms This November: All You Need to Know About this Action-Thriller
  3. Usurae Now Streaming on OTT: Plot, Cast, and Everything Else About This Tamil-Language Romantic Drama
  4. Supernova’s First Moments Show Olive-Shaped Blast in Groundbreaking Observations
  5. Intense Solar Storm With Huge CMEs Forced Astronauts to Take Shelter on the ISS
  6. Nearby Super-Earth GJ 251 c Could Help Learn About Worlds That Once Supported Life, Astronomers Say
  7. James Webb Telescope May Have Spotted First Generation of Stars in the Universe
  8. Coming-of-Age Web Series CO-ED to Stream on OTT Soon: Know When, Where to Watch Online
  9. Leonardo DiCaprio’s One Battle After Another Now Available for Rent on Prime Video: All You Need to Know
  10. Ajay Devgn's De De Pyaar De 2 OTT Debut Timeline Tipped: All You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.