Privacy Bypass Vulnerability Affects macOS Sequoia MDM Managed Devices

CVE-2024-44133
5.5MEDIUM

Key Information

Vendor
Apple
Status
Mac OS
Vendor
CVE Published:
17 September 2024

Badges

๐Ÿ˜„ Trended๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

Summary

The CVE-2024-44133 vulnerability affects macOS Sequoia MDM managed devices, allowing apps to bypass certain Privacy preferences. This issue has been exploited by the Adload malware to bypass macOS protections for the Safari browser, giving attackers unauthorized access to sensitive data such as cameras, microphones, and user locations. Apple released a fix for this vulnerability in macOS Sequoia 15, and Microsoft Defender for Endpoint has detected active exploitation of the flaw. Security teams are advised to patch the vulnerability as soon as possible, as it poses a serious risk of unauthorized access to user data. The exploitation of CVE-2024-44133 has been observed in the wild, indicating an active interest from threat actors. This highlights the importance of updating all macOS devices, actively monitoring for suspicious activity, and leveraging behavioral-based detection tools to identify and respond to potential threats.

News Articles

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit exists.

  • First article discovered by null

  • Vulnerability started trending.

  • Vulnerability published.

Collectors

NVD Database6 News Article(s)
.