Microsoft flags macOS bug allowing remote rootkit installs



Microsoft uncovered a critical security vulnerability (tracked as CVE-2024-44243) affecting Apple’s macOS (via Bleeping Computer). The threat allowed bad actors to circumvent the iPhone maker’s System Integrity Protection (SIP), granting them access to the macOS kernel by loading third-party code.

For context, SIP is a security feature designed to block malware from accessing important data in the operating system by restricting the root user account’s privileges in critical areas. As such, if the security feature is bypassed, the operating system becomes susceptible to malicious ploys by attackers, allowing them to make unauthorized changes to privileged and important files and folders.



Source link

Previous articleThe Wirecutter Show Episode 24: Strength Training Is for Everyone