An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" component. It allows attackers to modify the EFI flash-memory region that a crafted app that has root access.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041027 | vdb entry third party advisory |
https://support.apple.com/HT208849 | vendor advisory |
http://seclists.org/fulldisclosure/2019/Mar/45 | third party advisory mailing list |