macOS 11.3 Patches Security Vulnerability That Bypassed Built-In Malware Protections

Apple today confirmed to TechCrunch that the just-released macOS 11.3 software update patches a security vulnerability that reportedly could have allowed a hacker to remotely access a user's sensitive data by tricking a user into opening a spoofed document.

apple security banner
"All the user would need to do is double click — and no macOS prompts or warnings are generated," said security researcher Cedric Owens, who discovered the vulnerability in mid-March, according to the report. Owens developed a proof-of-concept app masquerading as a harmless document that exploits the bug to launch the Calculator app, but he said the vulnerability could be exploited for more nefarious purposes.

According to security researcher Patrick Wardle, the vulnerability was the result of a logic bug in macOS's underlying code.

"In simple terms, macOS apps aren't a single file but a bundle of different files that the app needs to work, including a property list file that tells the application where the files it depends on are located," explains TechCrunch. "But Owens found that taking out this property file and building the bundle with a particular structure could trick macOS into opening the bundle — and running the code inside — without triggering any warnings."

In addition to fixing the bug in macOS 11.3, Apple told TechCrunch it patched earlier macOS versions to prevent abuse, and updated macOS's built-in anti-malware system XProtect to block malware from exploiting the vulnerability. The report says the bug was exploited for months, but it's unclear how many users were impacted.

Related Forum: macOS Big Sur

Top Rated Comments

LV426 Avatar
23 months ago

Apple is definitely protecting the consumers.
Well, Apple definitely wasn’t protecting customers when they introduced this vulnerability.

There‘s a good write up of the disastrous security flaw here ('https://objective-see.com/blog/blog_0x64.html').
Score: 3 Votes (Like | Disagree)
TheYayAreaLiving ? Avatar
23 months ago
Apple is definitely protecting the consumers.
Score: 3 Votes (Like | Disagree)
Ethosik Avatar
23 months ago

This is why the Mac App Store should remain closed, walled and protected... oh, wait...
And the solution is to......remove the store and protected systems in place? There will always be bad things that slip through. The only....ONLY way to achieve 100% secure system is if the Apple App Review process takes months. Have Apple developers look through your code and REALLY test it. But would developers like this?

There are still murders, robberies, other criminal acts. Does that mean the police does nothing?
Score: 3 Votes (Like | Disagree)
RedTheReader Avatar
23 months ago

In simple terms, macOS apps aren't a single file but a bundle of different files that the app needs to work,
Everything Is a File™
Score: 2 Votes (Like | Disagree)
MauiPa Avatar
23 months ago
"The report says the bug was exploited for months, but it's unclear how many users were impacted." What report? A report is not mentioned in the article.
Score: 2 Votes (Like | Disagree)
lkrupp Avatar
23 months ago
Security updates for Mojave and Catalina out now that patch the same security issues.
Score: 2 Votes (Like | Disagree)

Popular Stories

dewey airtag

Report Highlights Danger of Using AirTags for Tracking Dogs

Monday January 30, 2023 1:45 pm PST by
AirTags may be a convenient way for tracking dogs that might get off leash or otherwise lost, but there are dangers associated with the practice, as outlined by a report from The Wall Street Journal. At 1.26 inches in diameter, AirTags are able to fit easily on a dog's collar, but that size also makes the tracking devices small enough to swallow, at least for a medium to large-sized dog, and ...
Multi Display CarPlay 1

Apple Launching All-New CarPlay Experience Later This Year With These 5 Features

Sunday January 29, 2023 10:15 am PST by
In June 2022, Apple previewed the next generation of CarPlay, promising deeper integration with vehicle functions like A/C and FM radio, support for multiple displays across the dashboard, personalization options, and more. Apple says the first vehicles with support for the next-generation CarPlay experience will be announced in late 2023, with committed automakers including Acura, Audi,...
General iOS 16 Feature Yellow

Five New iOS Features Coming to Your iPhone Later This Year

Tuesday January 31, 2023 11:58 am PST by
Apple has previously announced several upcoming iOS features that are expected to be added to the iPhone this year. Some of the features could be introduced with iOS 16.4, which should enter beta testing soon, while others will arrive later in the year. Below, we have recapped five new iOS features that are expected to launch in 2023, such as an Apple Pay Later financing option for purchases ...
maxresdefault

Kuo: Apple to Release Foldable iPad With Carbon Fiber Kickstand in 2024

Monday January 30, 2023 12:55 am PST by
Apple will launch a foldable iPad with a carbon fiber kickstand sometime next year, according to analyst Ming-Chi Kuo. Subscribe to the MacRumors YouTube channel for more videos. In a series of tweets, Kuo said he expects an "all-new design foldable iPad" to be the next big product launch in the iPad lineup, with no other major iPad releases in the next nine to 12 months. The analyst said he...
Apple Silicon Teal Feature

The Next Big Apple Silicon Device May Not Be a Mac or iPad

Wednesday February 1, 2023 3:57 am PST by
Apple's next device with an Apple silicon chip may not be a Mac or an iPad, but rather an advanced external display, according to recent reports. The display, which is rumored to arrive this year, is expected to sit somewhere between the $1,599 Studio Display and the $4,999 Pro Display XDR – but more exact information about the device's positioning and price point is as yet unknown. While ...
MKBHD HomePod 2 White Ring Stain

New HomePod Can Still Stain Some Wooden Surfaces

Tuesday January 31, 2023 8:29 am PST by
When the original HomePod launched in 2018, it was discovered that the speaker can leave white rings on some wooden surfaces. Now, well-known YouTuber Marques Brownlee has confirmed that the issue persists to a lesser extent with the new HomePod. In a side-by-side test, he showed that the white second-generation HomePod left a white ring on the wooden surface that he placed the speaker on,...
tim cook data privacy day

Apple Violated U.S. Labor Laws With Anti-Leak Email

Monday January 30, 2023 3:43 pm PST by
Apple violated United States labor laws when it sent out an email warning employees about leaking confidential information about the company, the National Labor Relations Board (NLRB) said today in a ruling shared by Bloomberg. Rules that Apple has established around leaks "tend to interfere with, restrain or coerce employees" from the exercise of their rights under the National Labor...