macOS Big Sur 11.4 Addresses Vulnerability That Could Let Attackers Take Secret Screenshots

macOS Big Sur 11.4, which was released this morning, addresses a zero-day vulnerability that could allow attackers to piggyback off of apps like Zoom, taking secret screenshots and surrepetiously recording the screen.

jamf malware secret screenshots
Jamf, a mobile device management company, today highlighted a security issue that allowed Privacy preferences to be bypassed, providing an attacker with Full Disk Access, Screen Recording, and other permissions without a user's consent.

The bypass was actively exploited in the wild, and was discovered by Jamf when analyzing XCSSET malware. The XCSSET malware has been out in the wild since 2020, but Jamf noticed an uptick in recent activity and discovered a new variant.

Once installed on a victim's system, the malware was used specifically for taking screenshots of the user's desktop with no additional permissions required. Jamf said that it could be used to bypass other permissions as well, as long as the donor application the malware piggybacked off of had that permission enabled.

Jamf has a full rundown on how the exploit worked, and the company says that Apple addressed the vulnerability in macOS Big Sur 11.4, Apple confirmed to TechCrunch that a fix has indeed been enabled in macOS 11.4, so Mac users should update their software as soon as possible.

Top Rated Comments

Kung gu Avatar
9 months ago
11.4 also fixes excessive ssd writes.

PSA: The SSD disk write issues have been fixed in 11.4 which came out today. The person who found the issue in first place says it was a result of a kernel bug and he also says 11.4 addresses the issue.
Update to 11.4 if your on M1 macs.
Users on this thread also report lower disk writes on 11.4.


[MEDIA=twitter]1396374313591140357[/MEDIA]
Score: 17 Votes (Like | Disagree)
Apple_Robert Avatar
9 months ago

OK just read the report by JAMF. So it piggybacks on fake Xcode projects, then requires the user to grant access through the Terminal and also through System Preferences. I'm glad this was found and dealt with, but it seems like it's a pretty weak exploit since nearly all of these behaviors should alert a user with more than 2 brain cells to stop the process
Unfortunately, a lot of people click accept without really thinking about what they are giving system access to and for what reason.
Score: 11 Votes (Like | Disagree)
deevey Avatar
9 months ago

Unfortunately, a lot of people click accept without really thinking about what they are giving system access to and for what reason.
And that folks, is why iOS should remain locked down tight :)
Score: 10 Votes (Like | Disagree)
Rigby Avatar
9 months ago

I assume this will be backported?
According to the post by JAMF it only affects MacOS 11. The security updates for Mojave ('https://support.apple.com/en-us/HT212531') and Catalina ('https://support.apple.com/en-us/HT212530') that also came out today do not list it.
Score: 8 Votes (Like | Disagree)
Guyferd Avatar
9 months ago

So how was it installed? The usual pirated software? Tricking users into downloading it as a fake utility or game?
OK just read the report by JAMF. So it piggybacks on fake Xcode projects, then requires the user to grant access through the Terminal and also through System Preferences. I'm glad this was found and dealt with, but it seems like it's a pretty weak exploit since nearly all of these behaviors should alert a user with more than 2 brain cells to stop the process
Score: 8 Votes (Like | Disagree)
TheYayAreaLiving ? Avatar
9 months ago
Thank you for the heads up. Hide your identity and yourself people!!!



Attachment Image
Score: 7 Votes (Like | Disagree)

Related Stories

First Look Big Sur Feature2

Apple Releases macOS Big Sur 11.2 With Bug Fixes for Bluetooth, External Displays, iCloud Drive, and More

Monday February 1, 2021 10:10 am PST by
Apple today released macOS Big Sur 11.2, the second major update to the macOS Big Sur operating system that launched in November. macOS Big Sur 11.2 comes more than a month after the release of macOS Big Sur 11.1. The new ‌‌macOS Big Sur‌ 11.2‌ update can be downloaded for free on all eligible Macs using the Software Update section of System Preferences. According to Apple's...
macOS Big Sur Feature Purple

Apple Seeds Second Beta of macOS Big Sur 11.4 to Developers [Update: Public Beta Available]

Tuesday May 4, 2021 10:19 am PDT by
Apple today seeded the second beta of an upcoming macOS Big Sur 11.4 update to developers for testing purposes, with the new beta coming two weeks after the release of the first macOS Big Sur 11.4 beta. Developers can download the ‌‌‌macOS Big Sur‌‌‌ 11.4 beta using the Software Update mechanism in System Preferences after installing the proper profile from the Apple Developer...
iOS 14 on iPhone feature emergency

Apple Seeds First Public Betas of iOS 14.7, iPadOS 14.7, and macOS Big Sur 11.5

Thursday May 20, 2021 10:11 am PDT by
Apple today seeded the first public betas of iOS 14.7, iPadOS 14.7, and macOS Big Sur 11.5 to public beta testers, one day after seeding first betas to developers. Public beta testers who have signed up for the beta testing program can download the iOS and iPadOS‌ 14.7 updates over the air after installing the proper certificate from the Public Beta website on an iOS device. macOS Big Sur...
macOS Big Sur Feature Purple

Apple Releases macOS Big Sur 11.3.1 With Fixes for WebKit Security Issues

Monday May 3, 2021 10:26 am PDT by
Alongside iOS 14.5.1 and watchOS 7.4.1, Apple today also released macOS Big Sur 11.3.1, which the company says "provides important security updates". According to the full security notes for the release, it addresses a memory corruption issue and an integer overflow in WebKit that could both be exploited using maliciously crafted web content. Apple says it aware of a report that these issues ...
sudo bug macos

Root Access Sudo Bug Found to Affect macOS Big Sur

Wednesday February 3, 2021 9:20 am PST by
A sudo bug that can grant an attacker root access has been discovered to affect macOS Big Sur (via ZDNet). The security vulnerability, identified last week as "CVE-2021-3156" by the Qualys Security Team, affects sudo, which is a program that allows users to run commands with the security privileges of another user, such as an administrator. The bug triggers a "heap overflow" in sudo that...
macOS Big Sur Feature Purple

Apple Seeds First Beta of macOS Big Sur 11.4 to Developers [Update: Public Beta Available]

Wednesday April 21, 2021 10:26 am PDT by
Apple today seeded the first beta of an upcoming macOS Big Sur 11.4 update to developers for testing purposes, with the new beta coming while the macOS 11.3 beta is still in testing. Developers can download the ‌‌‌macOS Big Sur‌‌‌ 11.4 beta using the Software Update mechanism in System Preferences after installing the proper profile from the Apple Developer Center. According...
macOS Big Sur Feature Blue

Update to macOS 11.4 NOW - Someone Could Be Spying On You

Sunday May 30, 2021 9:40 am PDT by
Apple's recently released macOS Big Sur 11.4 update addresses a serious security vulnerability, so all users should complete the software update immediately. Jamf, a mobile device management company, raised a major security issue in macOS Big Sur that allowed attackers to piggyback apps like Zoom to surreptitiously take screenshots and record the screen. The exploit allowed a user's Privacy...
macOS Big Sur Feature Orange

Apple Releases macOS Big Sur 11.4 With Apple Podcasts Subscription Support

Monday May 24, 2021 10:08 am PDT by
Apple today released macOS Big Sur 11.4, the fourth major update to the macOS Big Sur operating system that launched in November 2020. macOS Big Sur comes one month after the release of macOS Big Sur 11.3, an update that added M1 optimizations, AirTag integration, and more. The new ‌‌‌‌macOS Big Sur‌‌‌ 11.4 update can be downloaded for free on all eligible Macs using the...

Popular Stories

safari icon blue banner

Safari Bug Allows Websites to Track Your Recent Browsing Activity in Real Time [Updated]

Sunday January 16, 2022 3:37 pm PST by
A bug in WebKit's implementation of a JavaScript API called IndexedDB can reveal your recent browsing history and even your identity, according to a blog post shared on Friday by browser fingerprinting service FingerprintJS. In a nutshell, the bug allows any website that uses IndexedDB to access the names of IndexedDB databases generated by other websites during a user's browsing session....
iPhone 14 Mock pill and hole thumb

ProMotion Now Expected to Remain Exclusive to iPhone 14 Pro Models, Not Expand to Entire Lineup

Sunday January 16, 2022 8:56 am PST by
Continuing the tradition set with the iPhone 13 Pro, only the highest-end iPhone 14 models will feature Apple's ProMotion display technology, according to a respected display analyst. Ross Young, who on multiple occasions has detailed accurate information about Apple's future products, said in a tweet that ProMotion will not be expanded to the entire iPhone 14 lineup and will remain...
iPad Air Feature 2 green

New Apple Products Filed in Regulatory Database, Likely Including New iPhone SE and iPad Air

Tuesday January 18, 2022 6:11 am PST by
Apple today filed unreleased iPhone and iPad models in the Eurasian Economic Commission database, as spotted by French blog Consomac. The filings likely represent the rumored third-generation iPhone SE, fifth-generation iPad Air, and potentially more. The unreleased iPhone models have the identifiers A2595, A2783, and A2784, while the unreleased iPad models have the identifiers A2588, A2589, ...
AirPods 3 New Firmware Feature

Apple Updates AirPods 3 Firmware to Version 4C170

Tuesday January 18, 2022 11:46 am PST by
Apple today released a new 4C170 firmware update for the AirPods 3, an update from the prior 4C165 that was made available in December. Apple does not offer details on what's included in new firmware updates for the AirPods‌, so we don't know what improvements or bug fixes the new firmware brings. There is no standard way to upgrade the ‌AirPods‌‌ software, but firmware is...
iphone 5g mmwave

U.S. Airlines Warn of 'Catastrophic' Crisis With Impending 5G Rollout, AT&T and Verizon Agree to Delay Around Airports

Tuesday January 18, 2022 10:35 am PST by
Verizon and AT&T's upcoming rollout of new C-Band 5G technology could cause chaos and lead to widespread delays of passenger and cargo flights, major U.S. airlines said on Monday in a letter sent to the White House National Economic Council, the FAA, and the FCC (via Reuters). "Unless our major hubs are cleared to fly, the vast majority of the traveling and shipping public will essentially...
iphone se 2020 top

iPhone SE With Larger 5.7-Inch Display May Launch in 2023, 'iPhone SE+ 5G' Also Rumored

Monday January 17, 2022 6:46 am PST by
Apple is planning to release a fourth-generation iPhone SE with a larger 5.7-inch display as early as 2023, according to display industry consultant Ross Young, who has proven to be a reliable source of information for future Apple products. The fourth-generation iPhone SE has until now been rumored to launch in 2024, but Young now says a 2023 release is looking more likely....
tesla carplay solution

Developer Showcases Apple CarPlay Workaround for Teslas

Monday January 17, 2022 7:24 am PST by
A Tesla Model 3 owner has resorted to a workaround to implement Apple CarPlay in his vehicle, amid no sign of official support from Tesla (via Tesla North). Apple CarPlay and Apple Music support are among the most-requested Tesla features, but with no indication that Tesla is willing to implement Apple CarPlay in its vehicles, Polish developer Michał Gapiński took matters into his own...
ipad air 4 video

New iPad Air Rumored to Launch This Spring With A15 Chip, 5G, Center Stage Camera, and More

Saturday January 15, 2022 8:05 pm PST by
Apple is planning to release a fifth-generation iPad Air with similar features as the sixth-generation iPad mini, including an A15 Bionic chip, 12-megapixel Ultra Wide front camera with Center Stage support, 5G for cellular models, and Quad-LED True Tone flash, according to Japanese blog Mac Otakara. Citing reliables sources in China, the report claims that the new iPad Air could be...