{"id":258906,"date":"2021-05-25T21:53:24","date_gmt":"2021-05-25T18:53:24","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/a-new-macos-update-patches-0-day-exploit-that-let-hackers-screenshot-on-your-mac-review-geek\/"},"modified":"2021-05-25T21:53:24","modified_gmt":"2021-05-25T18:53:24","slug":"a-new-macos-update-patches-0-day-exploit-that-let-hackers-screenshot-on-your-mac-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/a-new-macos-update-patches-0-day-exploit-that-let-hackers-screenshot-on-your-mac-review-geek\/","title":{"rendered":"#A New macOS Update Patches 0-Day Exploit That Let Hackers Screenshot on Your Mac \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#A New macOS Update Patches 0-Day Exploit That Let Hackers Screenshot on Your Mac \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage wp-image-85036 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/a65c5d5c.jpg?width=1200\" alt=\"Colorful M1 MacBook\" width=\"1920\" height=\"1080\" data-credittext=\"Apple\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le<\/span><\/figcaption><\/figure>\n<p>Until today, malicious hackers have been exploiting a vulnerability in the latest macOS, allowing access to the microphone, webcam, recording the screen, or even taking screenshots on infected Macs. All of this happens without the user knowing or granting permission.<\/p>\n<p>This scary attack is finally getting patched with the latest macOS 11.4 update released on May 24th, 2021. If you haven\u2019t already, update your machine today, then\u00a0get an antivirus app.<\/p>\n<p>The zero-day was exploited by XCSSET, a piece of nasty malware\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/20\/h\/xcsset-mac-malware--infects-xcode-projects--uses-0-days.html\">discovered by security firm Trend Micro<\/a>\u00a0last August. XCSSET used what at the time were two zero-days aimed at developers, specifically their Xcode projects, which then got passed on to regular users.<\/p>\n<p>Initially, the researchers didn\u2019t know how far the vulnerability went. However, new reports claim the malware also exploits a third zero-day to take screenshots of the victim\u2019s screen secretly. None of this is good <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>, that\u2019s for sure.<\/p>\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-85040 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/8b8cb55a.jpg\" alt=\"Apple keeyboard backlight glow\" width=\"1920\" height=\"1080\" data-credittext=\"Cory Gunther\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"imagecredit\">Cory Gunther<\/span><\/figcaption><\/figure>\n<p>macOS is supposed to ask the user for permission before any app can record the screen, access the microphone, or access storage. Unfortunately, this sneaky malware can bypass that prompt completely by jumping into legitimate apps.<\/p>\n<p>At this point, it\u2019s not clear how many Macs are infected, but in a statement to\u00a0<em><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/techcrunch.com\/2021\/05\/24\/malware-xcsset-macos\/\">TechCrunch<\/a><\/em>, Apple confirmed\u00a0that the exploit is no longer an issue in the latest version, the macOS Big Sur 11.4 update. Keep in mind that this mostly targeted developer machines and not regular users.<\/p>\n<p>Either way, we\u2019ll say it one more time, update your Mac.\n<\/p><\/div>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/85025\/a-new-macos-update-patches-0-day-exploit-that-let-hackers-screenshot-on-your-mac\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#A New macOS Update Patches 0-Day Exploit That Let Hackers Screenshot on Your Mac \u2013 Review Geek&#8221; Apple Until today, malicious hackers have been exploiting a vulnerability in the latest macOS, allowing access to the microphone, webcam, recording the screen, or even taking screenshots on infected Macs. All of this happens without the user knowing&#8230;<\/p>\n","protected":false},"author":1,"featured_media":258907,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/a65c5d5c.jpg","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-258906","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/258906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=258906"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/258906\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/258907"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=258906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=258906"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=258906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}