Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    KoRn announce first UK and Ireland tour in over a decade with more 2026 European dates

    March 16, 2026

    Ray Dalio thinks the world looks like ‘pre-1945 times’ as we near the end of his ‘Big Cycle’

    March 16, 2026

    Cory Booker Drops The Hammer After Jake Tapper Tries To Blame Democrats For DHS Shutdown

    March 16, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»A Single Flaw Broke Every Layer of Security in MacOS
    Technology

    A Single Flaw Broke Every Layer of Security in MacOS

    By AdminAugust 13, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    A Single Flaw Broke Every Layer of Security in MacOS


    Every time you shut down your Mac, a pop-up appears: “Are you sure you want to shut down your computer now?” Nestled under the prompt is another option most of us likely overlook: the choice to reopen the apps and windows you have open now when your machine is turned back on. Researchers have now found a way to exploit a vulnerability in this “saved state” feature—and it can be used to break the key layers of Apple’s security protections.

    The vulnerability, which is susceptible to a process injection attack to break macOS security, could allow an attacker to read every file on a Mac or take control of the webcam, says Thijs Alkemade, a security researcher at Netherlands-based cybersecurity firm Computest who found the flaw. “It’s basically one vulnerability that could be applied to three different locations,” he says.

    After deploying the initial attack against the saved state feature, Alkemade was able to move through other parts of the Apple ecosystem: first escaping the macOS sandbox, which is designed to limit successful hacks to one app, and then bypassing the System Integrity Protection (SIP), a key defense designed to stop authorized code from accessing sensitive files on a Mac.

    Alkemade—who is presenting the work at the Black Hat conference in Las Vegas this week—first found the vulnerability in December 2020 and reported the issue to Apple through its bug bounty scheme. He was paid a “pretty nice” reward for the research, he says, although he refuses to detail how much. Since then Apple has issued two updates to fix the flaw, first in April 2021 and again in October 2021.

    When asked about the flaw, Apple said it did not have any comment prior to Alkemade’s presentation. The company’s two public updates about the vulnerability are light on detail, but they say the issues could allow malicious apps to leak sensitive user information and escalate privileges for an attacker to move through a system.

    Apple’s changes can also be seen in Xcode, the company’s development workspace for app creators, a blog post describing the attack from Alkemade says. The researcher says that while Apple fixed the issue for Macs running the Monterey operating system, which was released in October 2021, the previous versions of macOS are still vulnerable to the attack.

    There are multiple steps to successfully launching the attack, but fundamentally they come back to the initial process injection vulnerability. Process injection attacks allow hackers to inject code into a device and run code in a way that’s different to what was originally intended.

    The attacks are not uncommon. “It’s quite often possible to find the process injection vulnerability in a specific application,” Alkemade says. “But to have one that’s so universally applicable is a very rare find,” he says.

    The vulnerability Alkemade found is in a “serialized” object in the saved state system, which saves the apps and windows you have open when you shut down a Mac. This saved state system can also run while a Mac is in use, in a process called App Nap.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleThe Arctic Is Warming Four Times Faster Than the Rest of the Planet
    Next Article The best pillows for side sleepers in 2022, tried and tested

    RELATED POSTS

    The billionaires made a promise — now some want out

    March 16, 2026

    This At-Home Hair Growth System Just Dropped in Price

    March 15, 2026

    The MacBook Neo is ‘the most repairable MacBook’ in years, according to iFixit

    March 15, 2026

    How to Buy Used or Refurbished Electronics (2026)

    March 14, 2026

    ‘Not built right the first time’ — Musk’s xAI is starting over again, again

    March 14, 2026

    Best Dreo Spring Sale Deals: Air Fryer, Heater, Fans

    March 13, 2026
    latest posts

    KoRn announce first UK and Ireland tour in over a decade with more 2026 European dates

    KoRn have announced a new headline tour, which will see them play across the UK…

    Ray Dalio thinks the world looks like ‘pre-1945 times’ as we near the end of his ‘Big Cycle’

    March 16, 2026

    Cory Booker Drops The Hammer After Jake Tapper Tries To Blame Democrats For DHS Shutdown

    March 16, 2026

    Texas bans many China-linked medical devices over national security threats

    March 16, 2026

    The billionaires made a promise — now some want out

    March 16, 2026

    Our extinct Australopithecus relatives may have had difficult births

    March 16, 2026

    A Pale View of Hills review – a sombre adaptation…

    March 16, 2026
    Categories
    • Books (1,124)
    • Business (6,028)
    • Events (40)
    • Film (5,964)
    • Lifestyle (4,067)
    • Music (6,072)
    • Politics (6,028)
    • Science (5,381)
    • Technology (5,958)
    • Television (5,644)
    • Uncategorized (6)
    • US News (6,016)
    popular posts

    Win a Vinyl 12-Pack From 2022’s Best Rock + Metal Albums

    Oh what a year 2022 has been, and Loudwire Nights wants to make sure you…

    Clairo, Bartees Strange, and Bleachers Collaborate, St. Vincent Performs at Ally Coalition Talent Show: Watch

    December 20, 2023

    Trump Defends Wanting To Be A Dictator In Trainwreck Speech

    December 10, 2023

    Days of Our Lives Review Week of 5-09-22: The Devil Underestimates Everyone

    May 15, 2022
    Archives
    Browse By Category
    • Books (1,124)
    • Business (6,028)
    • Events (40)
    • Film (5,964)
    • Lifestyle (4,067)
    • Music (6,072)
    • Politics (6,028)
    • Science (5,381)
    • Technology (5,958)
    • Television (5,644)
    • Uncategorized (6)
    • US News (6,016)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Our extinct Australopithecus relatives may have had difficult births

    March 16, 2026

    A Pale View of Hills review – a sombre adaptation…

    March 16, 2026

    Everyone Who Got Bleeped at the 2026 Oscars — And What They Said

    March 16, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT