Experts complain: macOS vulnerabilities were reported in October last year, but Apple has not yet fixed them.
CTOnews.com, August 22 (Xinhua)-- Internet security expert Jeff Johnson released a report to Apple in October 2022, saying that a security vulnerability had been found in the application management (App Management) of macOS, but Apple has not yet fixed the vulnerability, so the details of the vulnerability were disclosed in August this year.
In a recent blog post, Johnson described in detail how the vulnerability works and how applications can use it to bypass the sandbox. There are six ways to gain the highest privileges, modify other applications without user permission, and obtain relevant information.
Johnson posted a blog post on its personal blog last October, outlining five ways to exploit the App Management vulnerability and saying it had noticed the sixth.
CTOnews.com learned from the report that Johnson said it reported the vulnerability to Apple immediately after it was discovered in October last year, and received an acknowledgement from Apple, but Apple has yet to fix it.
Johnson said that according to the rules of the security industry, details of the vulnerability can usually be disclosed after 90 days. Johnson has set aside a lot of time for Apple, but it hasn't been fixed yet.