国产三级大片在线观看-国产三级电影-国产三级电影经典在线看-国产三级电影久久久-国产三级电影免费-国产三级电影免费观看

Set as Homepage - Add to Favorites

【?? ??? ??】Enter to watch online.Mac users, download macOS 11.3 now to fix major security flaw

Source:Feature Flash Editor:hotspot Time:2025-07-03 14:28:41

The ?? ??? ??latest version of Apple's macOS comes with more than just a slew of fancy new features.

Buried inside macOS 11.3, which was released Monday morning, is a patch that fixes a critical vulnerability that was actively being exploited. This means that, yes, hackers or criminals or governments around the world were using this previously unreported bug for their own malicious ends.

That's according to Patrick Wardle, creator of the Mac security website and tool suite Objective-See. In a blog post timed to coincide with the release of macOS 11.3, Wardle explains just how serious the now-patched vulnerability is.

"This bug trivially bypasses many core Apple security mechanisms, leaving Mac users at grave risk," he writes.

Worryingly, Wardle and Jamf, a company that makes Apple management software for enterprise customers, were able to detect real malware exploiting this bug in the wild.

We reached out to Apple to both confirm Wardle's report and that macOS 11.3 contains a patch for this specific vulnerability. An Apple spokesperson confirmed that the latest version of macOS does include a fix for the underlying issues.

Discovered and reportedby Cedric Owens, an offensive security researcher, the bug — a logic flaw — reportedly allows a bad actor to bypass Apple's File Quarantine and Notarization requirements. It also, according to Apple, allows malware to skip the display of the Gatekeeper dialogue box but not bypass XProtect, Gatekeeper's malware detection, itself.

Why is this such a big deal?

"When a user downloads and opens an app, a plug-in, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered," explains an Apple support page. "Gatekeeper also requests user approval before opening downloaded software for the first time to make sure the user hasn’t been tricked into running executable code they believed to simply be a data file."

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

Presumably, then, this bug allows malware to skip that latter part of the Gatekeeper process.

In other words, bad actors are able to use this exploit to render many of the protective measures your computer takes to ensure downloaded files aren't malware useless.

Wardle demonstrates what this looks like in practice with a quick proof-of-concept video. In the video, embedded below, he shows how a downloaded file — which, to the user, looks like a PDF file — launches the calculator app.

Mashable ImageSneaky. Credit: Patrick wardle

And while Mac users don't necessarily need to worry about their calculator apps, they should worry about supposed PDF files being able to launch random applications on their computers without a bunch of alarm bells going off.

A hacker, after all, won't be interested in simple addition and subtraction.

Instead, someone exploiting the vulnerability might be able to launch a hidden program that could be involved any number of worrisome activities — think ransomware, stealing credit card digits, or worse.

Wardle was quick to clarify that exploiting this bug requires a user to first click or download something. Still, that's only a partial assurance.

"The majority of Mac malware infections are a result of users (naively, or mistakenly) running something they should not," explained Wardle over direct message. "And while such infections, yes, do require user interaction, they are still massively successful. In fact the recently discovered Silver Sparrow malware, successfully infected over 30,000 Macs in a matter of weeks, even though such infections did require such user interactions."

Thankfully, macOS 11.3 contains a fix — a fact Wardle says he was able to verify by reverse-engineering the latest operating system. "And good news," writes Wardle on his blog, "once patched macOS users should regain full protection."

SEE ALSO: How to stop your cell provider from sharing (some of) your data

That's good news indeed.

So go ahead and download macOS 11.3, and rest easy knowing that at least this specific Mac security problem has been fixed. Don't, however, throw all caution to the wind — please still think twice before downloading random files from the internet.

Topics Apple Cybersecurity

0.1583s , 9861.3203125 kb

Copyright © 2025 Powered by 【?? ??? ??】Enter to watch online.Mac users, download macOS 11.3 now to fix major security flaw,Feature Flash  

Sitemap

Top 主站蜘蛛池模板: 91精品国产综合久久国产大片 | 天天操天天爱综合 | 欧洲无线一线二线三线怎么区分 | 成人自慰女黄网站免费大全 | 波多野结衣av免费观看 | 91精品福利久久久 | 亚洲a成人片在线播放 | 国产自产第一区c国产 | 又大又爽又黄无码A片在线观看 | 一二三四日本无码影视 | 九九大香尹人视频免费 | 欧美激情一区二区A片成人 欧美激情一区二区三区AA片 | 高清自拍亚洲精品二区 | 久久精品免费大片国产大片 | 中文一区二区三区亚洲欧美 | 四虎影视永久免费观看地址 | 日本成本人片无码免费网站 | 色噜噜狠狠色综合久夜色撩人 | 日韩高清 一区二区 | 国产又黄又猛又粗又爽的A片漫 | 国产精品无打码在线播放 | 亚洲国产av综合精品 | 国产成人高清视频一区二区 | 最新日本一道免费一区二区 | 91亚洲国产亚洲综合尤物 | 中文字幕一精品亚洲无线一区 | 四虎影视最新免费观看 | 日本大片精品免费永久看NBA | 国产精品三级在线观看无码 | 一区二区欧美日韩 | 久久成人国产精品一区二区 | 乱肉杂交怀孕系列小说BL | 国产一区二区三黄色视频 | 国产熟妇无码A片AAA毛片视频 | 免费无码成人av在线播 | 日韩欧美综合一二三区 | 国内美女白浆视频久久网 | 国精品人妻无码一区二区三区软件 | 国产丰满老熟女厨房乱 | 亚洲自拍婷婷五月天 | 国产精品免费aⅴ片 |