BuggyCow: Google’s Project Zero team discovers rare ‘high severity’ flaw in Apple’s macOS

Google’s security research team, Project Zero, has released details about a “high-severity” flaw in Apple’s macOS operating system.

Dubbed ‘BuggyCow’, the vulnerability allowed anyone to modify a user-mounted file image without alerting the virtual management system. This essentially means cyber criminals could run codes on the mounted file image without user ever finding it out.

“XNU has various interfaces that permit creating copy-on-write copies of data between processes, including out-of-line message descriptors in mach messages. It is important that the copied memory is protected against later modifications by the source process; otherwise, the source process might be able to exploit double-reads in the destination process,” Google’s Project Zero researchers explained in a forum post.

Read more

You may also like

Comments are closed.