Most Viewed Content:

New Apple AirPods patent can monitor the wearer’s brainwaves and other biosignals

According to the latest list published by the United...

Samsung Galaxy S24 Series Added to IMEI Database: Revelation of the new Galaxy S series

Preparations are underway for the highly anticipated Samsung Galaxy...

Intel is preparing the Z890 motherboard chipset for Arrow Lake-S and Raptor Lake Refresh

Intel plans to launch Raptor Lake-S Refresh K processors...

Apple’s triple protection mechanism can be bypassed, vulnerability in macOS

At the recent Defcon hacker conference held in Las Vegas, security researcher Patrick Wardle showed a new vulnerability in macOS, which can bypass the triple protection mechanism set by Apple and steal Device Sensitive Data.

Apple has set up a triple protection mechanism, which is briefly summarized as follows:

  • Block malware launch or execution: App Store or access control combined with notarization
  • Prevent malware from running on customer systems: Gatekeeper, Notarization and XProtect
  • Fix executed malware: XProtect

Wardle reported to Apple last year a vulnerability that could bypass the triple protection mechanism and created related tools to verify the feasibility.

It’s just that Apple still hasn’t adopted the vulnerability he reported, so he decided to share the side-channel attack method he discovered at the Defcon hacker conference.

Wardle has so far discovered three attack methods, one of which requires root access to the target Mac device, while the other two do not require root privileges.

The translation part is as follows:

 "Wardle also discovered two vulnerabilities that don't require root access to execute, disabling the background task manager that sends persistent notifications to users and security monitoring products.

 One of the vulnerabilities exploits a bug in how the alarm system communicates with the core of a computer's operating system, known as the kernel.

 Another exploited a vulnerability that allowed users, even those without deep system privileges, to put processes to sleep. Wardle discovered that this feature can be manipulated to hijack persistent notifications before they reach the user."

Latest

Logitech G Pro X Superlight 2 Wireless Mouse Photos Revealed

Reddit community netizen tenzo66 recently posted a photo of...

Intel 4644 graphics drivers now support Madden NFL 24 and Wayfinder games

Intel has released the 31.0.101.4644 WHQL graphics driver, which...

Redmi Note 13 camera specs revealed, to feature 200-megapixel main camera

The source Kacper Skrzypek recently exposed the specifications of...

Ford: In-vehicle software service revenue will grow 1,000% in upcoming years

Ford Motor Company CEO Jim Farley expects revenue from...

Newsletter

Don't miss

Logitech G Pro X Superlight 2 Wireless Mouse Photos Revealed

Reddit community netizen tenzo66 recently posted a photo of...

Intel 4644 graphics drivers now support Madden NFL 24 and Wayfinder games

Intel has released the 31.0.101.4644 WHQL graphics driver, which...

Redmi Note 13 camera specs revealed, to feature 200-megapixel main camera

The source Kacper Skrzypek recently exposed the specifications of...

Ford: In-vehicle software service revenue will grow 1,000% in upcoming years

Ford Motor Company CEO Jim Farley expects revenue from...

Netflix cloud gaming is coming to Macs, PCs, and TVs

Netflix recently launched an app called "Game Controller" on...
Stephen Cruise
Stephen Cruisehttps://www.techgoing.com
Stephen Cruise is a senior editor covering latest smartphones, EVs, PC gaming, console, and tech with 11 years of experience.

Intel’s Arc A770 / A750 graphics cards have security vulnerabilities

Intel’s official website recently released an announcement, disclosing a vulnerability code named INTEL-SA-00812, which will affect some Iris A770 / A750 graphics cards sold...

Damo pSLC flagship SSD announced: 1280GB 42000 TBW, priced at RMB 2299

Damo recently previewed the consumer-grade pSLC flagship SSD announced today, model Virgo U, 1280GB RMB 2299, which is expected to be on sale soon. Damo...

DJI releases DJI image transmission receiver set, Priced at RMB 13499

DJI officially released a new DJI Transmission picture transmission receiver standard set, providing a highlights monitor set and standard set to choose from, RMB...