Apple’s MacOS Mojave released but with a major security vulnerability
Apple Inc. today released macOS 10.14 Mojave to the general public, but in a bad sign for the company, it has a major security vulnerability.
Mojave was announced in June 4 with a beta release being made available later that month. Finder and Quick Look have been upgraded with support added to the sidebar for full metadata for images, multimedia, documents and files, while Quicklook now integrates editor software Markup to recognize numerous types of media.
Most of the changes were under the hood, but a new native “dark mode” allows users to change the look and feel of the entire user interface to darken the display and, as it unexpectedly turns out, allow hackers to break into the macOS install.
Detailed by security researcher Patrick Wardle, a severe security flaw introduced in the dark theme allows unauthorized access to a users’ private data. Speaking to Bleeping Computer, Wardle explained that the vulnerability, which can be exploited by an unverified app, stems from the way Apple has implemented protections for privacy-related data.
Although not going into great detail about the technical aspects, a video shows Wardle attempting to access a user’s protected address book without success. Then he runs a bypass program, dubbed fittingly “breakMojave,” wherein Wardle locates a user’s address book, circumvents the privacy access controls and copies its contents to his desktop.
Wardle added that the bypass does not work with all of Mojave’s new privacy protection features and that hardware-based components such as the built-in webcam are unaffected.
Apple has not commented on the report, although Wardle said he attempted to reach out to the company before going public. Presumably, the vulnerability also existed in the beta versions of Mojave prior to its official release.
It’s not a good look for Apple given that it has long boasted that its software is more secure than that of Microsoft Windows.
Wardle said he will release more details about the vulnerability at a conference in November.
Image: Apple
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.