Microsoft Researchers Detail macOS Vulnerability That Could Let Attackers Gain User Data

Apple fixed the vulnerability through a macOS release last month.

Advertisement
By Jagmeet Singh | Updated: 13 January 2022 19:13 IST
Highlights
  • macOS vulnerability could allow attackers to bypass TCC tech
  • Apple acknowledged Microsoft efforts while informing users
  • macOS has TCC since 2012 to help users configure privacy settings

macOS users are recommended to install the latest update on their systems

Photo Credit: Gadgets 360/ Roydon Cerejo

Microsoft has detailed a vulnerability that existed in macOS which could allow an attacker to bypass its inbuilt technology controls and gain access to users' protected data. Dubbed “powerdir,” the issue impacts the system called Transparency, Consent, and Control (TCC) that has been available since 2012 to help users configure privacy settings of their apps. It could let attackers hijack an existing app installed on a Mac computer or install their own app and start accessing hardware including microphone and camera to gain user data.

As detailed on a blog post, the macOS vulnerability could be exploited by bypassing TCC to target users' sensitive data. Apple notably fixed the flaw in the macOS Monterey 12.1 update that was released last month. It was also fixed through the macOS Big Sur 11.6.2 release for older hardware. However, devices that are using an older macOS version are still vulnerable.

Advertisement

Apple is using TCC to help users configure privacy settings such as access to the device's camera, microphone, and location as well as services including calendar and iCloud account. The technology is available for access through the Security & Privacy section in System Preferences.

On top of TCC, Apple uses a feature that is aimed to prevent systems from unauthorised code execution and enforced a policy that restricts access to TCC to only apps with full disk access. An attacker can, though, change a target user's home directory and plant a fake TCC database to gain the consent history of app requests, Microsoft security researcher Jonathan Bar Or said in the blog post.

Advertisement

“If exploited on unpatched systems, this vulnerability could allow a malicious actor to potentially orchestrate an attack based on the user's protected personal data,” the researcher said.

Microsoft's researchers also developed a proof-of-concept to demonstrate how the vulnerability could be exploited by changing the privacy settings on any particular app.

Advertisement

Apple has acknowledged the efforts made by the Microsoft team in its security document. The vulnerability is traced as CVE-2021-30970.


What's most interesting about Apple's new MacBook Pros, M1 Pro and M1 Max silicon, AirPods (3rd Generation), and Apple Music Voice plan? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy F70 Pro 5G Debuts in India With These Features
  2. JioTag 2 Launched in India With Google Find Hub and Apple Find My Support
  3. Adidas Hyperboost Edge Review: Boost Reborn?
  4. iQOO Z11 to Debut in India With a Different Design Than the Chinese Model
  5. Vivo S2 Key Specifications Teased Ahead of August 6 India Launch
  6. Google Pixel 11 Series Could Start at $899; Specifications Surface Online
  7. Oppo A7 Pro Max Rear Camera Features Revealed
  8. Amazon Great Freedom Sale: Top Deals on Smartphones Revealed
  9. Apple Could Be Working on New Smart Glasses With Health Tracking Features
  10. Samsung Galaxy S27 Ultra, S27 Pro Rear Camera Configuration Leaked Online
  1. Sony Bravia 9 II 115-inch True RGB TV Launched in India With Backlight Master Drive Pro Tech: Price, Specifications
  2. iQOO Neo 11S Leak Hints at Bigger Battery, Custom Dimensity 9500 SoC
  3. Oppo Find X10 Ultra Leak Hints at 200-Megapixel Camera Upgrade, Premium Price Tag
  4. Sony Doesn't Expect Any Negative Impact on Gaming Business After Ending Disc Production
  5. Vivo S2 Key Specifications Confirmed Ahead of August 6 India Launch: 7,050mAh Battery, Dimensity 7360 Turbo, and More
  6. Amazon Great Freedom Sale: Deals on Projectors From Boat, Lumio, Zebronics and More Teased
  7. Samsung Galaxy S27 Pro, Galaxy S27 Ultra Leak Hint at a Triple Rear Camera System, Different Telephoto Shooters
  8. Researchers Warn of New Bitcoin Wallet Attacks as 448 BTC Is Swept From Hundreds of Addresses
  9. Samsung Galaxy F70 Pro 5G Launched in India With Snapdragon 6 Gen 3 Chip, 6,000mAh Battery: Price, Specifications
  10. Apple Caps Security Bug Reports Amid Surge in AI-Generated Findings: Report
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.