bgr.com
Security flaws in Microsoft Mac apps could let hackers spy on you
Cybersecurity group Cisco Talos identified vulnerabilities in Microsoft apps for Mac that could leave you vulnerable to hackers. According to the group, some Microsoft apps can be exploited and let hackers inject malicious libraries to gain entitlements and user-granted permissions, such as microphone access, camera, folders, screen recording, user input, and more.
Cisco Talos says there are eight vulnerabilities in various Microsoft Mac apps that let attackers bypass the operating system's permission model by using app permissions without prompting the user for any additional verification.
The group gives some examples: "An attacker could send emails from the user account without the user noticing, record audio clips, take pictures, or record videos without any user interaction." Interestingly, Microsoft considers these issues low risk, as the company claims users "need to allow loading of unsigned libraries to support plugins" and has declined to fix them.
Image source: José Adorno for BGR
According to Cisco Talos, Microsoft Outlook, Teams, PowerPoint, OneNote, Excel, and Word could be hacked because they use a feature called com.apple.security.cs.disable-library-validation entitlement. It could turn off security features and make apps vulnerable to library injection attacks.
Fortunately, in a lengthy blog post, the company explains that macOS offers enough protection, and users are unlikely to suffer from this attack. However, when an app is downloaded outside the Mac App Store, it makes it more possible for a hacker to bypass the app and Mac security and perform this attack.
The best way to protect yourself is to keep your Mac and Microsoft apps updated. Avoiding installing plugins for Microsoft apps could also help prevent security flaws on the Mac.
Also, it seems this attack hasn't been exploited, and regular users shouldn't worry too much about it. That said, you should always check your Mac's Settings to ensure only the apps you trust can access your microphone, camera, folders, and more.
Don't Miss: Millions of Google Pixels have shipped with a major security flaw
The post Security flaws in Microsoft Mac apps could let hackers spy on you appeared first on BGR.
Today's Top Deals
Today’s deals: $699 Apple Watch Ultra 2, self-bagging trash can, $349 Dyson V8 Plus vacuum, more
Today’s deals: $248 Sony XM5 earbuds, $180 Roomba, $13 Anker fast chargers, $19 Roku streamer, more
Today’s deals: $10 off school supplies, $189 Apple Watch SE, $140 FlexiSpot electric standing desk, more
Today’s deals: Pixel 9 preorder offers, $400 off Narwal Freo X Ultra, $500 off Sony OLED TV, more