Get a Pentest and security assessment of your IT network.

News

macOS Signature Validation Flaw Allows Malware Appeared to be Trusted

The vulnerability resides in how third-party vendors such as Google and Facebook checks the signed code to verify the integrity of the file. Affected vendors are Google, LittleSnitch, F-Secure-xFence, Yelp OSXCollector, VirusTotal, Carbon Black. The vulnerability went unnoticed for years and there is no evidence of this vulnerability being abused. The code signing API verifies the first binary in the Fat/Universal file to see who signs the executable without passing the flags SecRequirementRef, SecCSFlags, and SecCodeCheckValidity. The malicious binary must be adhoc signed and i386 compiled for an x86_64 bit target.”]

Source: https://gbhackers.com/macos-signature-validation-flaw/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin