Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 17, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 17, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 17, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 17, 2025

      Microsoft’s allegiance isn’t to OpenAI’s pricey models — Satya Nadella’s focus is selling any AI customers want for maximum profits

      May 17, 2025

      If you think you can do better than Xbox or PlayStation in the Console Wars, you may just want to try out this card game

      May 17, 2025

      Surviving a 10 year stint in dev hell, this retro-styled hack n’ slash has finally arrived on Xbox

      May 17, 2025

      Save $400 on the best Samsung TVs, laptops, tablets, and more when you sign up for Verizon 5G Home or Home Internet

      May 17, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      NodeSource N|Solid Runtime Release – May 2025: Performance, Stability & the Final Update for v18

      May 17, 2025
      Recent

      NodeSource N|Solid Runtime Release – May 2025: Performance, Stability & the Final Update for v18

      May 17, 2025

      Big Changes at Meteor Software: Our Next Chapter

      May 17, 2025

      Apps in Generative AI – Transforming the Digital Experience

      May 17, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft’s allegiance isn’t to OpenAI’s pricey models — Satya Nadella’s focus is selling any AI customers want for maximum profits

      May 17, 2025
      Recent

      Microsoft’s allegiance isn’t to OpenAI’s pricey models — Satya Nadella’s focus is selling any AI customers want for maximum profits

      May 17, 2025

      If you think you can do better than Xbox or PlayStation in the Console Wars, you may just want to try out this card game

      May 17, 2025

      Surviving a 10 year stint in dev hell, this retro-styled hack n’ slash has finally arrived on Xbox

      May 17, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Major Flaw in Microsoft Mac Apps Could Let Hackers Spy Through Mic and Camera

    Major Flaw in Microsoft Mac Apps Could Let Hackers Spy Through Mic and Camera

    August 20, 2024

    A critical vulnerability has been discovered in several popular Microsoft apps in Apple MacBook. The vulnerability could potentially allow hackers to steal user permissions from apps and gain unauthorized access to sensitive data like camera feeds and microphone recordings.  The vulnerability reportedly affects a wide range of Microsoft apps for macOS, including Outlook, Teams, Word, Excel, PowerPoint and OneNote.

    Vulnerability Details: Bypassing macOS Security Measures

    The vulnerability was discovered by security researchers from Cisco Talos. In its report, the researchers highlighted that the vulnerability resides in the way Microsoft apps handle libraries.

    Apple’s macOS has a framework known as Transparency Consent and Control (TCC), which manages app permissions to access things like location services, camera, microphone, library photos, and other files.

    Each app needs an entitlement to request permissions from TCC. Apps without these entitlements won’t even ask for permissions, and consequently won’t have access to the camera and other parts of the computer. However, the exploit allowed malicious software to use the permissions granted to Microsoft apps.

    “We identified eight vulnerabilities in various Microsoft applications for macOS, through which an attacker could bypass the operating system’s permission model by using existing app permissions without prompting the user for any additional verification,” the researchers explained. By exploiting this vulnerability, attackers can inject malicious libraries into Microsoft apps on a Mac.

    Source: CISCO Report

    Once injected, these malicious libraries can leverage the existing permissions granted to the Microsoft app (such as camera and microphone access) to spy on users like the example in the above image. Additionally, these libraries can steal other user permissions, potentially giving attackers broader control over the system.

    Potential Consequence of Vulnerability

    The potential consequences of this vulnerability are severe. Hackers could exploit it to:

    Spy on Users: Gain unauthorized access to a user’s camera and microphone, potentially recording video and audio conversations.
    Steal Sensitive Data: Access and steal sensitive data stored on the Mac, including documents, emails, and passwords.
    Escalate Privileges: Gain elevated privileges within the system, allowing them to perform actions with greater control.
    Disrupt System Functionality: Malicious libraries could disrupt the normal operation

    After researchers shared the report to Microsoft, the tech giant updated the Microsoft Teams and OneNote apps for macOS with changes to how these apps handle the library validation entitlement. However, Excel, PowerPoint, Word, and Outlook are still vulnerable to the exploit. Microsoft told researchers that it considered this exploit to be “low risk” since it relies on loading unsigned libraries to support third-party plugins.

    What Mac Users Can Do?

    While a permanent fix from Microsoft is still awaited, Mac users can take several steps to mitigate the risk associated with this vulnerability:

    Update Microsoft Apps: Regularly update your Microsoft apps to the latest versions. Updates often include security patches that address newly discovered vulnerabilities.
    Disable Unnecessary Permissions: Review and disable any permissions granted to Microsoft apps that you don’t consider essential. For example, if you don’t use video conferencing features in Teams, you can disable camera access for the app.

    The report raised questions about the vulnerability of third-party plugins in Apple products.

    “It’s also important to mention that it’s unclear how to securely handle such plug-ins within macOS’ current framework. Notarization of third-party plug-ins is an option, albeit a complex one, and it would require Microsoft or Apple to sign third-party modules after verifying their security,” the report said.

    “MacOS could also introduce a user prompt, akin to the resource permissions in TCC, enabling users to decide whether to load a specific third-party plug-in. This would provide a more controlled means of granting access without broadly compromising security,” it added.

    Source: Read More

    Hostinger
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleResearchers Uncover TLS Bootstrap Attack on Azure Kubernetes Clusters
    Next Article Iranian Cyber Group TA453 Targets Jewish Leader with New AnvilEcho Malware

    Related Posts

    Development

    February 2025 Baseline monthly digest

    May 17, 2025
    Development

    Learn A1 Level Spanish

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Power Apps and Components: Understanding Components and Their Role in App Development

    Development

    Laravel Debugbar: 4 Less-Known Features

    Development

    Preserving Collection Keys in Laravel API Resources

    Development

    How we test portable power stations at ZDNET in 2024

    Development

    Highlights

    Rejoice: Overwatch 2’s popular 6v6 mode is here to stay — at least during Season 16 News & Updates

    Rejoice: Overwatch 2’s popular 6v6 mode is here to stay — at least during Season 16

    April 11, 2025

    Overwatch 2’s 6v6 Open Queue mode has proven to be extremely popular — so much…

    Google pulls controversial AI ad from Olympics coverage amid backlash

    August 3, 2024

    Google Releases Agent Development Kit (ADK): An Open-Source AI Framework Integrated with Gemini to Build, Manage, Evaluate and Deploy Multi Agents

    April 9, 2025

    Meta AI Introduces EWE (Explicit Working Memory): A Novel Approach that Enhances Factuality in Long-Form Text Generation by Integrating a Working Memory

    January 4, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.