Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Friday, April 30th, 2021

    Time Event
    3:21p
    Serious MacOS Vulnerability Patched

    Apple just patched a MacOS vulnerability that bypassed malware checks.

    The flaw is akin to a front entrance that’s barred and bolted effectively, but with a cat door at the bottom that you can easily toss a bomb through. Apple mistakenly assumed that applications will always have certain specific attributes. Owens discovered that if he made an application that was really just a script—code that tells another program what do rather than doing it itself—and didn’t include a standard application metadata file called “info.plist,” he could silently run the app on any Mac. The operating system wouldn’t even give its most basic prompt: “This is an application downloaded from the Internet. Are you sure you want to open it?”

    More.

    << Previous Day 2021/04/30
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org