Search

Microsoft Researchers Detail macOS Vulnerability That Could Let Attackers Gain User Data

Apple fixed the vulnerability through a macOS release last month.

Advertisement
Highlights
  • macOS vulnerability could allow attackers to bypass TCC tech
  • Apple acknowledged Microsoft efforts while informing users
  • macOS has TCC since 2012 to help users configure privacy settings
Microsoft Researchers Detail macOS Vulnerability That Could Let Attackers Gain User Data

macOS users are recommended to install the latest update on their systems

Photo Credit: Gadgets 360/ Roydon Cerejo

Microsoft has detailed a vulnerability that existed in macOS which could allow an attacker to bypass its inbuilt technology controls and gain access to users' protected data. Dubbed “powerdir,” the issue impacts the system called Transparency, Consent, and Control (TCC) that has been available since 2012 to help users configure privacy settings of their apps. It could let attackers hijack an existing app installed on a Mac computer or install their own app and start accessing hardware including microphone and camera to gain user data.

As detailed on a blog post, the macOS vulnerability could be exploited by bypassing TCC to target users' sensitive data. Apple notably fixed the flaw in the macOS Monterey 12.1 update that was released last month. It was also fixed through the macOS Big Sur 11.6.2 release for older hardware. However, devices that are using an older macOS version are still vulnerable.

Apple is using TCC to help users configure privacy settings such as access to the device's camera, microphone, and location as well as services including calendar and iCloud account. The technology is available for access through the Security & Privacy section in System Preferences.

On top of TCC, Apple uses a feature that is aimed to prevent systems from unauthorised code execution and enforced a policy that restricts access to TCC to only apps with full disk access. An attacker can, though, change a target user's home directory and plant a fake TCC database to gain the consent history of app requests, Microsoft security researcher Jonathan Bar Or said in the blog post.

“If exploited on unpatched systems, this vulnerability could allow a malicious actor to potentially orchestrate an attack based on the user's protected personal data,” the researcher said.

Microsoft's researchers also developed a proof-of-concept to demonstrate how the vulnerability could be exploited by changing the privacy settings on any particular app.

Apple has acknowledged the efforts made by the Microsoft team in its security document. The vulnerability is traced as CVE-2021-30970.


What's most interesting about Apple's new MacBook Pros, M1 Pro and M1 Max silicon, AirPods (3rd Generation), and Apple Music Voice plan? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Advertisement

Related Stories

Popular Mobile Brands
  1. Flipkart Independence Day Sale 2025 Will Start on This Date
  2. Redmi Pad 2 Review: The Budget Tablet Done Right
  3. Upcoming Honor Smartphone Could Feature a Massive 10,000mAh Battery
  4. iQOO 15 Teased Again as iQOO Prepares to Launch Its Next Flagship Phone
  5. Samsung's One UI 8 Beta Programme for Galaxy S24 Series Begins Today
  6. Realme P4 Series To Launch in India On This Date; Price Range Revealed
  1. SpaceX to Fly Italian Science Experiments to Mars on Starship in 2026
  2. SWOT Satellite Captures Tsunami Wave After Kamchatka Quake
  3. Inspector Zende OTT Release Date: When and Where to Watch Manoj Bajpayee Starrer Thriller Online?
  4. Microsoft Lens App to Be Retired at the End of This Year, Company Suggests Users Switch to Copilot
  5. Smartphone Shipments in India Grew 7.3 Percent YoY in Q2 2025; Vivo Retains Top Spot
  6. Microsoft Faces Lawsuit Over Decision to End Windows 10 Support
  7. Oppo Find X9 Ultra to Feature Bigger Dual-Cell Battery Than Find X8 Ultra, Tipster Claims
  8. Samsung Galaxy M17 5G Reportedly Listed on Google Play Console Ahead of Debut
  9. Samsung Galaxy Tab A11 Live Image Surfaces on Safety Korea Database in Sign of Imminent Launch
  10. ChatGPT’s Health Advice Sends 60-Year-Old Man to the Hospital, Raises Questions on Its Reliability
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »