Technology

New Mac exploit lets hackers take near-total control without detection

A cyber-security team has just discovered a dangerous new security exploit in Apple’s Mac OS X, leaving the operating system almost completely vulnerable to hackers.

Discovered by SentinelOne, the exploit exists in System Identity Protection (SIP), Apple’s kernel defense feature. It was first introduced in El Capitan, the latest version of Mac OS, and is responsible for preventing users from changing system files through a “rootless” system and keeps even administrator accounts from accessing specific files without first disabling SIP.

“Our researchers recently uncovered a major flaw which allows for local privilege escalation and bypass of System Integrity Protection, Apple’s newest protection feature,” said SentinelOne in a blog post.

It seems that SIP can be attacked directly by a hacker to access a system all while evading detection from the operating system due to the difficulty of spotting the exploit once it’s implemented. Then, it can be used to escalate privileges and also to bypass system integrity. To make it even more perilous, they can further use SIP as a weapon to prevent the system from repairing itself.

“This vulnerability not only reveals a major security flaw in OS X, but also provides further evidence that exploits can be extremely stealthy, and at times, virtually impossible to detect.”

Apple has been notified of this zero-day exploit and a patch is on the way but it really is shockingly-worrying how even Apple’s Mac OS, known as a more secure and malware-free alternative to Windows, is vulnerable to an attack.

Sponsored
Rehan Ahmed

I cover startups, review gadgets and talk about latest developments in the technology industry. Get in touch through rehan@techjuice.pk.

Share
Published by
Rehan Ahmed
Tags: slider

Recent Posts

Yahoo Surprises Users with Its Latest Android Launcher

Third-party apps have long been a staple of the Android ecosystem, but their appeal has…

1 hour ago

Phase-II Review of PTCL-Telenor Deal Finalized by CCP

ISLAMABAD: The Competition Commission of Pakistan (CCP) has completed its Phase-II review of Pakistan Telecommunication…

1 hour ago

Xiaomi’s SU7 Achieves New Production Record, Driving Q3 Growth

Xiaomi has shattered records by producing 100,000 vehicles in just 230 days. This is nearly…

3 hours ago

Teachers Can Now Access OpenAI’s Free AI Course

OpenAI, in collaboration with nonprofit organization Common Sense Media, announced on Wednesday the launch of…

4 hours ago

WhatsApp-Inspired Updates Under Testing in Google Messages

Google is exploring a revamped image-sharing interface in its Messages app, taking cues from WhatsApp…

4 hours ago

Create AI Video Backgrounds with YouTube Shorts’ Dream Screen

When it comes to online video streaming, YouTube is among the most well-known options. Every…

4 hours ago