Apple in macOS Big Sur 11.3 fixed a bug that could have allowed attackers to bypass the Mac’s security mechanisms with a malicious document.
The software flaw allowed attackers to create a malicious application that could masquerade as a document, TechCrunch reported Monday. Security researcher Cedric Owens first discovered the bug in March.
According to Owens, “all the user would need to do is double click — and no macOS prompts or warnings are generated.” The researcher created a proof-of-concept app that exploited the flaw to launch the Calculator app.
Although Owens’ demonstration app was harmless, a malicious attacker could have leveraged the vulnerability to remotely access sensitive data or other information on a user’s machine by tricking them into clicking a spoofed document.
Read more at AppleInsider.com
