Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
How a major vulnerability in Microsoft's apps allowed hackers to break into Macs
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • How a major vulnerability in Microsoft's apps allowed hackers to break into Macs

How a major vulnerability in Microsoft's apps allowed hackers to break into Macs

FP Staff • August 20, 2024, 12:11:21 IST
Whatsapp Facebook Twitter

Microsoft has downplayed the risks associated with this exploit, categorising it as “low risk.” Nevertheless, Microsoft has rolled out updates to some of its apps, including Teams and OneNote, to address the way these applications handle library validation

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
How a major vulnerability in Microsoft's apps allowed hackers to break into Macs
The security gap could allow an attacker to inject their malicious code into an app like Microsoft Teams or Outlook, and gain access to a Mac computer's camera and microphone. Image Credit: Pexels

A critical vulnerability in Microsoft’s apps for MacOS was discovered recently. This vulnerability allowed hackers to spy on Mac users by exploiting flaws in popular applications like Microsoft Outlook and Teams.

Security researchers from Cisco Talos, a cybersecurity division known for its focus on malware and system vulnerabilities, recently detailed how this security gap could be used by attackers to access sensitive components like a Mac’s microphone and camera without the user’s knowledge or consent.

STORY CONTINUES BELOW THIS AD

The flaw in Microsoft’s Mac Apps
The vulnerability stems from how Microsoft apps interact with MacOS’s Transparency Consent and Control (TCC) framework, which is designed to manage app permissions.

More from Tech
How ChatGPT is becoming everyone’s BFF and why that’s dangerous How ChatGPT is becoming everyone’s BFF and why that’s dangerous America ready for self-driving cars, but it has a legal problem America ready for self-driving cars, but it has a legal problem

TCC ensures that apps must request specific entitlements to access features such as the camera, microphone, or location services. Normally, apps without these entitlements cannot even ask for permission, effectively blocking unauthorised access.

However, the exploit discovered by Cisco Talos shows that malicious actors can inject harmful software into Microsoft apps, and then hijack the permissions already granted to those apps.

This means that once an attacker successfully injects their code into an app like Microsoft Teams or Outlook, they could gain access to a Mac computer’s camera and microphone, enabling them to record audio or take photos without any prompts to the user.

Impact Shorts

More Shorts
America ready for self-driving cars, but it has a legal problem

America ready for self-driving cars, but it has a legal problem

Alibaba, Baidu begin using own AI chips as China shifts away from US tech amid Nvidia row

Alibaba, Baidu begin using own AI chips as China shifts away from US tech amid Nvidia row

The researchers identified eight distinct vulnerabilities within various Microsoft applications for MacOS. These vulnerabilities allow hackers to bypass MacOS’s permission model by leveraging the entitlements that have already been granted to these apps. With this exploit, attackers can effectively spy on users without any direct interaction from the user, putting their privacy at significant risk.

STORY CONTINUES BELOW THIS AD

Microsoft’s Response
Despite the severity of the findings, Microsoft has downplayed the risks associated with this exploit, categorising it as “low risk.” According to Microsoft, the attack depends on the use of unsigned libraries to support third-party plugins, which they view as an uncommon and unlikely scenario.

Nevertheless, in response to the reported vulnerabilities, Microsoft has rolled out updates to some of its apps, including Teams and OneNote, to address the way these applications handle library validation.

However, other widely used apps like Excel, PowerPoint, Word, and Outlook remain vulnerable, with no immediate fix in sight. This partial response has raised concerns among security experts, who question Microsoft’s decision to disable certain security measures like library validation, which were originally intended to protect users from such attacks. The researchers argue that by bypassing these safeguards, Microsoft is potentially exposing its users to unnecessary security risks.

The Need for Enhanced Security Measures
The Cisco Talos researchers also pointed out that Apple could take additional steps to strengthen MacOS’s TCC framework. One suggested improvement is for the system to prompt users whenever third-party plugins are loaded into apps that have already been granted sensitive permissions.

STORY CONTINUES BELOW THIS AD

This would add an extra layer of security, ensuring that users are aware of any unusual or unauthorised activity.

As it stands, the combination of Microsoft’s handling of app entitlements and Apple’s current TCC framework leaves room for vulnerabilities that could be exploited by determined attackers. Both companies may need to take more proactive measures to protect users from these emerging threats, especially as the reliance on digital communication tools continues to grow.

In the meantime, Mac users are advised to remain vigilant, particularly if they use Microsoft apps on their devices, and to keep their software up to date to minimise the risk of exploitation.

End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

America ready for self-driving cars, but it has a legal problem

America ready for self-driving cars, but it has a legal problem

US self-driving cars may soon ditch windshield wipers as the NHTSA plans to update regulations by 2026. State-level rules vary, complicating nationwide deployment. Liability and insurance models are also evolving with the technology.

More Impact Shorts

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV