Moneycontrol PRO
Loans
Loans
HomeTechnologyHow hackers may have used Microsoft apps to spy on Mac users

How hackers may have used Microsoft apps to spy on Mac users

Eight Microsoft applications are vulnerable to library injection attacks potentially allowing unauthorised camera and microphone access for data theft from Apple’s macOS devices.

August 20, 2024 / 17:01 IST
Office

Researchers from Cisco Talos, a renowned cybersecurity firm, have discovered and identified eight security vulnerabilities in Microsoft apps available for macOS, that potentially allow attackers to access the user’s cameras and microphones. These vulnerabilities could also steal other types of sensitive data compromising system security.

The affected Microsoft apps include widely used programs like Word, Outlook, Excel, OneNote, Teams, and more. The attack is based on injecting malicious libraries into Microsoft apps to gain their entitlements and user-granted permissions. It stems from how Microsoft apps interact with macOS’s Transparency Consent and Control (TCC) framework, which is designed to manage app permissions.

These Microsoft apps also use a feature called com.apple.security.cs.disable-library-validation entitlement. It could turn off security features and make these applications potentially dangerous for the user. This loophole also compromises the integrity of the affected apps, increasing the risk of exploitation by hackers or malicious actors.

In response to Cisco Talos findings, Microsoft has acknowledged the existence of these security flaws on its applications and has categorised these as ‘low risk.’ The tech giant has also updated some of its apps, including Teams and OneNote, to address the way these applications handle library validation.

However, Microsoft has not fixed other vulnerable apps such as Excel, PowerPoint, Word, and Outlook. This makes these apps susceptible to attacks. It has also declined to address these specific vulnerabilities, and the researchers argue that by bypassing these safeguards, Microsoft is potentially exposing its users to unnecessary security risks.

Therefore, you should always check your macOS’s device settings to ensure they are updated timely and do not have unauthorised access to its microphone, camera, or other hardware.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Sandip Chakraborty
first published: Aug 20, 2024 05:01 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347