
A significant security flaw (CVE-2024-44133) has been discovered in Apple's macOS TCC framework, which could allow hackers to bypass user consent for accessing sensitive data such as location, camera, and microphone. Microsoft revealed that this vulnerability, dubbed HM Surf, also bypasses privacy controls in the Safari browser. Additionally, hackers are now directing users to Terminal to bypass Gatekeeper in macOS Sequoia, enabling the execution of malicious code. A proof-of-concept (PoC) for this flaw has been published, highlighting the severity of the issue.
macOS Vulnerability Could Expose User Data, Microsoft Warns https://t.co/JsoCgJGEGe
macOS Gatekeeper Bypassed to Execute Malicious Code : https://t.co/d4NtvE3RzX https://t.co/nOGefOB8c7
macOS HM Surf flaw in TCC allows bypass Safari privacy settings: https://t.co/sG0gu66Xbr by Security Affairs #infosec #cybersecurity #technology #news