HT TECH wants to start sending you push notifications. Click allow to subscribe

BuggyCow: Google’s Project Zero team discovers rare ‘high severity’ flaw in Apple’s macOS

Google has disclosed a “high severity” flaw in the macOS kernel which allows anyone to access PC without user’s knowledge.

By: HT CORRESPONDENT
Updated on: Aug 20 2022, 13:39 IST
Google discloses ‘high severity’ flaw in macOS (Getty Images/iStockphoto)

Google's security research team, Project Zero, has released details about a "high-severity" flaw in Apple's macOS operating system.

Dubbed 'BuggyCow', the vulnerability allowed anyone to modify a user-mounted file image without alerting the virtual management system. This essentially means cyber criminals could run codes on the mounted file image without user ever finding it out.

You may be interested in

Mobiles Tablets Laptops
4% OFF
Apple iPhone 15 Pro Max 1TB
  • Black Titanium
  • 8 GB RAM
  • 1 TB Storage
₹177,990₹184,900
Buy now
Apple iPhone 15 512GB
  • Black
  • 6 GB RAM
  • 512 GB Storage
₹109,900
Buy now
2% OFF
Google Pixel 7 5G
  • Obsidian
  • 8 GB RAM
  • 128 GB Storage
₹58,990₹59,999
Buy now
31% OFF
Google Pixel 7 Pro 5G
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹58,990₹84,999
Buy now
Apple MacBook Pro M1 Max MK1A3HN A Ultrabook
  • Space Grey
  • 32 GB RAM
  • 1 TB SSD
₹319,900
Buy now
Apple MacBook Pro M3 MR7J3HN A Ultrabook
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹169,900
Buy now
Apple MacBook Air MRE92HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 256 GB SSD
₹134,900
Buy now
Apple MacBook Pro M2 MNEH3HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 256 GB SSD
₹100,000
Buy now
3% OFF
Apple iPad Pro 12 9 2022 WiFi 2TB
  • Silver
  • 16 GB RAM
  • 2 TB Storage
₹216,191₹222,900
Buy now
3% OFF
Apple iPad Pro 11 2022 WiFi 1TB
  • Silver
  • 16 GB RAM
  • 1 TB Storage
₹147,328₹151,900
Buy now
3% OFF
Apple iPad Pro 12 9 2022 WiFi plus Cellular 256GB
  • Silver
  • 8 GB RAM
  • 256 GB Storage
₹133,750₹137,900
Buy now
3% OFF
Apple iPad Pro 11 2022 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹123,081₹126,900
Buy now

"XNU has various interfaces that permit creating copy-on-write copies of data between processes, including out-of-line message descriptors in mach messages. It is important that the copied memory is protected against later modifications by the source process; otherwise, the source process might be able to exploit double-reads in the destination process," Google's Project Zero researchers explained in a forum post.

Also read: Looking for a smartphone? To check mobile finder click here.

The researchers pointed out that copy-on-write (CoW) behaviour works with anonymous memory as well as file mappings. They further said that the "memory pressure can cause the pages holding the transferred memory to be evicted from the page cache after the destination process has started."

ALSO READ: WebAuthn: The new web standard aims to make passwords obsolete

"Later, when the evicted pages are needed again, they can be reloaded from the backing filesystem. This means that if an attacker can mutate an on-disk file without informing the virtual management subsystem, this is a security bug," the researchers added.

Google's research team reportedly informed Apple about the vulnerability in November 2018. The team gave 90-days to fix the loophole before making it public. According to 9to5Google, Apple will be releasing the fix in its future macOS update.

ALSO READ: 14.5% Indian companies could not detect any cyber attack in 2018: F-Secure Report

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 05 Mar, 19:19 IST
Tags:

Sale

Mobiles Tablets Laptops
13% OFF
Apple iPhone 13 256GB
  • Blue
  • 4 GB RAM
  • 256 GB Storage
₹60,499₹69,900
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
5% OFF
Apple iPhone 15 Pro
  • Black Titanium
  • 8 GB RAM
  • 128 GB Storage
₹127,990₹134,900
Buy now
10% OFF
Apple iPhone 15 Plus 256GB
  • Black
  • 6 GB RAM
  • 256 GB Storage
₹80,590₹89,900
Buy now
2% OFF
Apple iPad Pro 12 9 2021 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹139,900₹142,900
Buy now
17% OFF
Apple iPad Air 2020
  • Space Gray
  • 4 GB RAM
  • 64 GB Storage
₹49,999₹59,900
Buy now
2% OFF
Apple iPad Pro 11 WiFi Cellular 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹109,900₹111,900
Buy now
2% OFF
Apple iPad Pro 11 WiFi 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹109,900₹111,900
Buy now
38% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹32,790₹52,999
Buy now
27% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹21,990₹29,990
Buy now
29% OFF
Asus ROG Zephyrus G14 GA401QH BM072TS Laptop
  • Grey
  • 8 GB RAM
  • 512 GB SSD
₹65,990₹92,990
Buy now
35% OFF
Asus VivoBook Pro 15 M6500RC HN741WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹67,990₹104,990
Buy now