A malicious application may be able to overwrite arbitrary files. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Mojave. An issue with path validation logic for hardlinks was addressed with improved path sanitization.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT212529 | vendor advisory |
https://support.apple.com/en-us/HT212531 | vendor advisory |