The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to read arbitrary files.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT212147 | vendor advisory |
https://support.apple.com/en-us/HT212146 | vendor advisory |
https://support.apple.com/en-us/HT212148 | vendor advisory |
https://support.apple.com/en-us/HT212149 | vendor advisory |
https://support.apple.com/kb/HT212326 | vendor advisory |
https://support.apple.com/kb/HT212327 | vendor advisory |
http://seclists.org/fulldisclosure/2021/Apr/51 | third party advisory mailing list |