Google Project Zero Reveals 'High Severity' macOS Flaw

Advertisement
By Gadgets 360 Staff | Updated: 6 March 2019 09:58 IST
Highlights
  • Apple is yet to release a fix for the disclosed vulnerability
  • The company is said to be working on a patch, but there is no timeline
  • The flaw disclosed by Google Project Zero is said to be hard to exploit

Google Project Zero team had revealed the flaw to Apple on November 30, 2018

Google's Project Zero team has revealed a “high severity” macOS kernel flaw that allows an attacker to modify a user-owned mounted filesystem without the knowledge of macOS memory manager. Even after getting information about the flaw on November 30, 2018, Apple is yet to release a patch for the same, leaving macOS users vulnerable to possible exploitation. Project Zero team has a strict automatic 90-days disclosure policy, which means even if a company has not released a fix 90 days after being informed by Google, the team will publicly reveal the security vulnerability. The team does offer a grace period in select cases but that hasn't happened with Apple in this instance. 

The Project Zero team writes that they found a loophole in the copy-on-write (CoW) protection of macOS, which manages the computer's memory and makes sure that a process doesn't change the data shared by other processes. The team discovered that when a mounted filesystem image is changed directly, macOS doesn't propagate the information to its memory manager. So basically, an attacker can unmount a file system and then remount it with changed data and the system would be none wiser.

The Wired notes that it will be really hard to exploit the flaw disclosed by Project Zero and it needs the prospective victim to already have some kind of malware present on their computer.

Advertisement

Apple is yet to publicly comment on the security flaw, but it is said to be working on patch, which will arrive with a future release.

Advertisement

"We've been in contact with Apple regarding this issue, and at this point no fix is available," the researchers told ZDNet in a statement. "Apple are intending to resolve this issue in a future release, and we're working together to assess the options for a patch."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S24 Ultra Deal Revealed Ahead of Amazon GIF Sale
  2. Xiaomi Announces Offers on These Products Ahead of Amazon, Flipkart Sales
  3. iQOO 15 Design Leak Reveals Colour-Changing Panel: See Benchmark Scores
  4. Amazon Sale 2025: Check Top Deals on These iQOO Smartphones
  5. Borderlands 4 Faces Performance Issues on PS5 Pro, Gearbox Confirms Patch
  6. Nothing Ear 3 With 'Super Mic' Feature, Up to 45dB ANC Launched: See Price
  7. Best Flagship Headphones Deals During the Amazon Great Indian Festival Sale
  8. Ray-Ban Meta Gen 2 Glasses Are Here With a Massive Camera Upgrade
  9. These Companies Fired Over 10K Employees Between July and September 2025
  1. Microsoft's Xbox Full-Screen Experience Leaks on Other Windows Handhelds Ahead of ROG Xbox Ally Debut
  2. Cellecor Comet CBS-05 Pro Bluetooth Speaker Launched in India: Price, Features
  3. Samsung Galaxy S24 Ultra, Galaxy S24 FE, Galaxy A55 5G and More to Go on Sale With Discounts During Festive Season
  4. Coinbase Urges US DOJ Action as SEC Mulls Dropping Lawsuit Against Crypto Exchange
  5. Vivo V60 Lite 4G Design, Specifications Leaked; Tipped to Launch With Snapdragon 685 SoC, 6,500mAh Battery
  6. Nothing Ear 3 Launched With Super Mic Feature, Up to 45dB Active Noise Cancellation: Price, Features
  7. Nvidia Bets Big on Intel With $5 Billion Stake and Chip Partnership
  8. Samsung Project Moohan XR Headset Launch Reportedly Postponed to October
  9. Samsung Galaxy S25 Series' Android-16-Based One UI 8 Update Rollout Expands to India
  10. Xiaomi Announces Festive Offers on Redmi Note 14 Series, Xiaomi Pad 7, QLED TVs and More
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.