It is advisable to install the latest updates for macOS Big Sur and Monterey

We've always known that updating to the latest operating systems was more than just testing the new features that Apple developers have implemented. Improvements and correction of errors are always included, which sometimes seem to be just paperwork, but we know well that this is not the case. In fact, the latest updates to macOS Big Sur and macOS Monterey included a series of improvements and they avoided exposure to a new macOS vulnerability.

Microsoft has reported that a new vulnerability in macOS that 'could allow an attacker to circumvent the technology of transparency, consent and control (TCC) of the operating system ». Apple fixed this vulnerability last month as part of the macOS Big Sur and macOS Monterey updates. So, oddly enough, Microsoft is encouraging all users to install the latest versions of the aforementioned operating systems.

Apple released the new update for this vulnerability with the release of macOS Monterey 12.1 and macOS Big Sur 11.6.2 on December 13. At the time, Apple simply explained that an app could have been able to bypass privacy preferences. For this reason and as a solution to the problem, updates were released in order to solve the vulnerability.

Now Microsoft has published Through a detailed note on the blog about the exact problem and the solution provided. Written by the Microsoft 365 Defender research team, the blog post explains what TCC is. A technology that prevents applications access personal information of users without their consent and prior knowledge.

Given this, if a malicious person gains full disk access to the TCC databases, they could edit it to grant arbitrary permissions to any application they choose. Including its own malicious application. Nor would the affected user be asked to allow or deny such permissions. That will allow lThe application runs with settings that you may not have known or consented to.


Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.