Most Viewed Content:

Cygnus space cargo spacecraft arrives at International Space Station with only half of its solar array

NASA astronaut Nicole Mann, backed up by NASA astronaut...

Google to bring PWA application backup & restore function for Chrome/android

According to thespAndroid reports, GitHub's Chromium repository recently added...

India’s censorship body gave power to remove pirated Movies from platforms

India’s Ministry of Information and Broadcasting announced that its...

Apple’s triple protection mechanism can be bypassed, vulnerability in macOS

At the recent Defcon hacker conference held in Las Vegas, security researcher Patrick Wardle showed a new vulnerability in macOS, which can bypass the triple protection mechanism set by Apple and steal Device Sensitive Data.

Apple has set up a triple protection mechanism, which is briefly summarized as follows:

  • Block malware launch or execution: App Store or access control combined with notarization
  • Prevent malware from running on customer systems: Gatekeeper, Notarization and XProtect
  • Fix executed malware: XProtect

Wardle reported to Apple last year a vulnerability that could bypass the triple protection mechanism and created related tools to verify the feasibility.

It’s just that Apple still hasn’t adopted the vulnerability he reported, so he decided to share the side-channel attack method he discovered at the Defcon hacker conference.

Wardle has so far discovered three attack methods, one of which requires root access to the target Mac device, while the other two do not require root privileges.

The translation part is as follows:

 "Wardle also discovered two vulnerabilities that don't require root access to execute, disabling the background task manager that sends persistent notifications to users and security monitoring products.

 One of the vulnerabilities exploits a bug in how the alarm system communicates with the core of a computer's operating system, known as the kernel.

 Another exploited a vulnerability that allowed users, even those without deep system privileges, to put processes to sleep. Wardle discovered that this feature can be manipulated to hijack persistent notifications before they reach the user."

Latest

Starting from 48,900, Geely Panda Karting officially starts pre-sale

Geely Panda Karting officially started pre-sale. The pre-sale price...

Ford: Expand charging network, fuel/ hybrid/ pure electric in parallel

Recently, Ford released the company's comprehensive annual report for...

Chery’s two new cars are exposed, targeting overseas markets

Recently, some media exposed the actual cars of two...

New Trumpchi Shadow Leopard to launch on May 1, upgraded performance rims

Recently, we learned from the official that the 2024...

Newsletter

Don't miss

Starting from 48,900, Geely Panda Karting officially starts pre-sale

Geely Panda Karting officially started pre-sale. The pre-sale price...

Ford: Expand charging network, fuel/ hybrid/ pure electric in parallel

Recently, Ford released the company's comprehensive annual report for...

Chery’s two new cars are exposed, targeting overseas markets

Recently, some media exposed the actual cars of two...

New Trumpchi Shadow Leopard to launch on May 1, upgraded performance rims

Recently, we learned from the official that the 2024...

Samsung Galaxy S25 Ultra expected to feature 5000mAh + 45W Combo

Technology media WccFtech recently reported that Samsung will not...
Stephen Cruise
Stephen Cruisehttps://www.techgoing.com
Stephen Cruise is a senior editor covering latest smartphones, EVs, PC gaming, console, and tech with 11 years of experience.

BYD’s Denza Z9 GT set for May Technical Conference ahead of mid-year launch

Since the spring of this year, more and more car companies have opened “answer questions from netizens” sessions. Yesterday evening, BYD Denza released the...

Chery Sterra ET launch on May 9: Starting from NT$239,000 for the pure electric version

According to official Sterra news, the Sterra brand’s second model/first SUV model, the Sterra ET, will be launched on May 9. Positioned as a...

Audi RS5 Avant test car spy photos exposed

Although Audi’s RS series sedans and station wagons have always been known for their performance, their exterior designs are often somewhat conventional and lack...