Skip to main content
  1. Home
  2. Computing
  3. Apple
  4. Web
  5. News

Researchers exploit flaws in two browsers installed on MacOS devices

Add as a preferred source on Google

Researchers recently uncovered security flaws in two web browsers for MacOS enabling hackers to gain access to Mac devices. The first flaw reared its head in Safari during the first day of Pwn2Own 2018, giving the hacker full control of the Touch Bar. Meanwhile, Check Point Research stumbled across a nasty bug in Google Chrome granting access to the administrative or any other user account without the need for a password. 

First up, Samuel “5aelo” Gross from Phoenhex targeted Safari during his Pwn2Own hack attempt using a MacOS kernel Elevation of Privileges, meaning he found a way to get permission to use resources only reserved for the lowest level of MacOS that even administrators can’t access. He did this by exploiting a bug in Safari’s Java-based just-in-time (JIT) compiler optimization combined with a flaw in the MacOS platform. 

Recommended Videos

“He used a combination of a JIT optimization bug in the browser, a macOS logic bug to escape the sandbox, and finally a kernel overwrite to execute code with a kernel extension to successfully exploit Apple Safari,” Zero Day Initiative explains a bit more thoroughly. “He left a message for us on the touchbar once he was complete.” 

Meanwhile, Check Point Research’s discovery in Google Chrome has nothing to do with the Pwn2Own 2018 event. Instead, one of the firm’s security analysts noted “unexpected behavior” while examining the Remote Desktop component of Google’s Chrome browser for MacOS. He noticed that he could sign onto the remote Mac device as a guest user, but jump into another active session, even one used by the administrator, without entering a password. 

As the report explains, typically there is someone logged onto a MacOS device but locked with a password when not in use. In turn, guests don’t actually have an account: They can simply access the Mac device without a password and are typically restricted in some fashion by the administrator. All files created by the guest are stored in a temporary folder and deleted once they log off the device. 

That said, if guests access the Mac remotely using Chrome’s extension, they see a screen displaying the current user’s password entry field and an option to sign on as a guest. After clicking on the guest icon and proceeding to the home screen, the guest will see the current user’s desktop rather than the temporary sandboxed guest account. Meanwhile, the source MacOS device displays the guest account on its screen. 

The company said it reported the Chrome issue to Google on February 15, but the search engine giant believes the Remote Desktop login screen is not “a security boundary.” Regardless, Check Point Research felt the need to go public with the issue given many Mac owners provide guest access to their devices. 

Chrome’s Remote Desktop component is a handy way to troubleshoot a remote relative’s computer or grab files from home. At least two computers need Chrome installed, with one serving as the “source” machine providing an access code to the second machine.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Your favorite Edge extension may stop working soon as Microsoft follows Chrome’s lead
Microsoft has announced the transition to Manifest V3, gradually phasing out older browser extensions.
Microsoft Edge on PC and Mobile Featured

Microsoft Edge is finally making the same controversial move that Google Chrome did earlier this year, and it could mean the end of some of the browser's most popular ad blockers. Microsoft has announced that Edge is officially transitioning its extensions ecosystem to Manifest Version 3 (MV3), Google's newer extension platform that promises better security, privacy, and performance. As part of that shift, the browser will gradually stop supporting older Manifest V2 (MV2) extensions over the coming months, meaning legacy extensions such as the original uBlock Origin will eventually stop working in Edge.

What is Manifest V3, and why is Microsoft adopting it?

Read more
Help, I’m talking to my computer. It’s remarkably convenient and utterly embarrassing.
Oh look, I have become the guy who randomly starts talking while staring at his computer.
Person using a laptop.

A decade ago, Google introduced voice typing with the Gboard app on Android, and a year later, the perk landed on iPhones with the keyboard app. I never paid much attention to it. The biggest reason was that it was just not accurate. 

The big promise was a whole new way of interacting with our phones, but it was never good enough to make me quit tapping, or swiping on an on-screen keyboard. Fast forward to 2026, I'm talking to my computer. In fact, this whole article was dictated and copy-pasted in WordPress. 

Read more
Cloudflare’s new browser Kitesurf is designed for AI agents to browse the internet
AI agents just got their own browser that lets them browse the internet more efficiently.
cloudflare-kitesurf-browser-for-ai

Cloudflare just entered the AI-browser race with a twist. Instead of building another Chrome alternative for people, the company launched Kitesurf, a cloud-hosted browser made only for AI agents. Since autonomous AI systems are increasingly the ones doing the actual browsing and scrolling online, Cloudflare just made its to claim that space.

https://twitter.com/Cloudflare/status/2085372860650913898

Read more