Patrick Wardle of Digita Security has revealed a security flaw in Apple’s software. Malware could exploit ‘synthetic clicks’ automated clicks or keystrokes made by an app in the interests of accessibility. Apple introduced a whitelist that limited access to synthetic clicks to applications approved by the user. But for reasons of backwards compatibility it was discovered that Apple had built in some exceptions to this rule through the Transparency Consent and Control system (TCC) Wardle says the verification is incomplete, so they only check that the app is signed by who they think it should be.”]

