macOS Exploit Published on the Last Day of 2017 (bleepingcomputer.com)
An anonymous reader shares a report: On the last day of 2017, a security researcher going online by the pseudonym of Siguza published details about a macOS vulnerability affecting all Mac operating system versions released since 2002, and possibly earlier. Siguza did not notify Apple in advance, so at the time of writing, there is no fix for this flaw. Despite the doom and gloom, the vulnerability is only a local privilege escalation (LPE) flaw that can only be exploited with local access to a computer or after an attacker has already got a foothold on a machine. The vulnerability grants root access to an attacker. The issue affects the IOHIDFamily macOS kernel driver, a component that handles various types of user interactions. Siguza said he read about various flaws in this component and took a look at it to find new ways to compromise iOS, Apple's mobile operating system, where IOHIDFamily is also deployed. The expert says he found the LPE flaw in the IOHIDFamily code specific to macOS versions only. In a tweet, Siguza said, "My primary goal was to get the write-up out for people to read. I wouldn't sell to blackhats because I don't wanna help their cause. I would've submitted to Apple if their bug bounty included macOS, or if the vuln was remotely exploitable.
Oh, it's "only a local privilege escalation". No worries then.
I would never do this. Too many companies turn and sue when you bring it to their attention.
I would sell it on the dark web instead. Safer and more profitable.
Without a visionary in charge, the company cuts corners and is losing major ground in 2018. If I owned Apple stock it'd be sold today.
The best thing that could happen to Apple (and to Apple users) is if Elon Musk took control of Apple without him losing any influence at Tesla or SpaceX.
These companies are a good fit, really. Tesla would have Apple product design power and Apple could benefit from someone clearly on Steve Jobs' visionary and operational level.
Something like this or similar: https://www.marketwatch.com/st...
The dangers of knowledge trigger emotional distress in human beings.
The NSA collects every message it can so I expect China's government to do the same. Unless the US is more a police state than China
Reading the writeup I would say this guy really knows his Mac internals. Apple is getting better at security though: the last root exploit only required you to type "root" and no password. And the one before that required a single line of script to get root.
It just hasn't been made public yet...
http://pythonsweetness.tumblr.com/post/169166980422/the-mysterious-case-of-the-linux-page-table
A vulnerability from back in 2017 is probably old enough to not be worth fixating.
I'll see your senator, and I'll raise you two judges.
I read IOHIDFamily, which contain IO and HID. Obviously, but, this means USB to me, and, doing basic math, I'm wondering whether a no-name Chinese USB device could use this hole to implant some malware.
Totof