A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.
Link | Tags |
---|---|
https://support.apple.com/en-us/121234 | release notes vendor advisory |
https://support.apple.com/en-us/121238 | release notes vendor advisory |
https://support.apple.com/en-us/121247 | release notes vendor advisory |