28 September 2020

Apple fixed four dangerous vulnerabilities in macOS


Apple fixed four dangerous vulnerabilities in macOS

Apple has patched four vulnerabilities in macOS Catalina, High Sierra, and Mojave.

One of the vulnerabilities (CVE-2020-9973) affects the Model I / O component. Its exploitation, which includes the processing of a malicious USD file, could lead to arbitrary code execution or a DoS condition. The vulnerability affects all versions of macOS. The problem was reported by a Cisco Talos researcher, and Apple has fixed it.

Another issue (CVE-2020-9968) that also affects all versions of macOS is a sandbox vulnerability. It can be exploited by a malicious application to access restricted files. Adam Chester of TrustedSec reported his findings to Apple, and the company patched the vulnerability.

The tech giant has also patched a remote arbitrary code execution vulnerability (CVE-2020-9961) that could be exploited using malicious images. An issue discovered by Xingwei Lin of the Ant Group Light-Year Security Lab affects the ImageIO component in macOS High Sierra and Mojave.

The fourth issue (CVE-2020-9941) only affects macOS High Sierra and affects the Mail component. Its exploitation allows a remote attacker to "change the state of the application."

Back to the list

Latest Posts

Cyber Security Week in Review: May 10, 2024

Cyber Security Week in Review: May 10, 2024

In brief: Google fixes yet another Chrome 0Day, Dell suffers a data breach, the LockBit leader identified, and more.
10 May 2024
Massive BogusBazaar fraud ring steals credit cards from thousands of victims

Massive BogusBazaar fraud ring steals credit cards from thousands of victims

As of April 2024, approximately 22,500 domains were active.
9 May 2024
Poland’s government institutions targeted in Russian cyberespionage campaign

Poland’s government institutions targeted in Russian cyberespionage campaign

The incident marks the latest in a string of Russian cyberattacks aimed at NATO-allied nations supporting Ukraine.
9 May 2024