Skip to main content
  1. Home
  2. Computing
  3. Apple
  4. News

Apple MacOS hit with yet another critical system security issue

Add as a preferred source on Google

Apple has been held in high regard as a company that has always been focused on the security of its product offerings; however, a new kernel flaw was recently found within the company’s MacOS desktop operating system. The latest news comes just months after a critical security flaw was shown to bypass MacOS Mojave’s system security and a massive flaw allowed eavesdropping via Apple’s FaceTime videotelephony software. This time around, the problem is at the heart of MacOS — the XNU kernel.

XNU is the operating system kernel for MacOS that has been in use as far back as the mid-1990s — a kernel is the core computer program that allows for software to communicate with a device’s hardware. The most recent flaw was discovered by the Project Zero team at Google, which aims to identify deficiencies in consumer software. According to Google, they were able to take advantage of the kernel’s copy-on-write function; this allowed the team to modify data on a disk without the entire system being aware of the change.

Recommended Videos

When a flaw is discovered, Project Zero follows a procedure where it first presents an issue to the company responsible for the software, with a set deadline before the information is released to the general public. Project Zero made Apple aware of the flaw in November 2018; however, as of February 28th, Apple has yet to patch the issue. Ben Hawkes of Project Zero does note that Apple is “intending to resolve the issue in a future release, and we’re working together to assess the options for a patch.”

Google’s Project Zero is a team of industry recognized security professionals, including Jann Horn, the researcher who was critical to the discovery of both the Meltdown and Spectre vulnerabilities affecting both Intel and ARM-based processors. In regards to Apple’s problem with the MacOS XNU kernel, the team at Google has introduced a concept code solution for the challenge. The kernel of an operating system is central to all processes, and it is possible that Apple is approaching the issue with great tact, albeit a bit slow for its users. For the utmost security, be sure to always keep your copy of MacOS up to date.

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
Comu’s tiny AI recorder can turn your meetings into slides, emails, and action plans
Comu Action Pro records for up to 70 hours and supports more than 113 languages
Comu Action Pro AI voice recorder in hand

AI voice recorders that can capture meetings, transcribe conversations, and generate summaries are becoming increasingly common. Flowtica's Scribe, for example, puts those capabilities inside a pen that can also be used for handwritten notes.

Comu, formerly known as Comulytic, is taking the concept a step further with the Action Pro, which is a pocket-sized AI recorder capable of turning recorded conversations into editable presentations, follow-up emails, meeting briefs, documents, and action plans. The device has a dedicated AI button that lets users request these materials using voice commands.

Read more
Microsoft threatened legal action, and this researcher just dropped a new Windows bug anyway
Windows Defender was supposed to protect you. Right now, it's the problem.
Microsoft account

Microsoft's legal threats clearly didn't scare off security researcher Nightmare Eclipse. Just weeks after the company warned it might pursue researchers who release undisclosed bugs outside its official channels, Nightmare Eclipse published a fresh Windows vulnerability, and it's a nasty one.

What exactly does ShieldBreak do?

Read more
Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop
AI made phishing too easy, so Microsoft is closing the door on SMS logins.
Computer, Electronics, Laptop

Microsoft just sent a warning to IT admins, and it's a big one. The company wants everyone to stop using SMS and voice-based authentication, and it's citing AI-powered phishing as the main reason.

Why is Microsoft killing SMS authentication?

Read more