Jamf on Tuesday revealed the details of an iCloud vulnerability that was fixed with the release of iOS 18, iPadOS 18, and macOS 15 Sequoia. The vulnerability involved the Transparency, Consent, and Control (TCC) subsystem, and when successfully exploited, would allow an app to access contact information, GPS locations, photos, are other sensitive data.
The TCC in iOS, iPadOS, and macOS alerts the user when an app wants to access sensitive data; the user can then grant or deny access. In this instance, the vulnerability allows a malicious app to intercept and redirect the files when a user moves or copies files from the Files app, without alerting the user that the app is accessing the data. The files are then saved to an area defined by the malicious app and can be moved to a remote server. This vulnerability was recorded as CVE-2024-44131 in the National Vulnerability Database.
Read more at Macworld.com

