{"id":393457,"date":"2022-01-12T18:15:20","date_gmt":"2022-01-12T15:15:20","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/update-your-mac-to-avoid-the-powerdir-attack\/"},"modified":"2022-01-12T18:15:20","modified_gmt":"2022-01-12T15:15:20","slug":"update-your-mac-to-avoid-the-powerdir-attack","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/update-your-mac-to-avoid-the-powerdir-attack\/","title":{"rendered":"#Update Your Mac to Avoid the \u201cpowerdir\u201d Attack"},"content":{"rendered":"<p><strong>&#8220;#Update Your Mac to Avoid the \u201cpowerdir\u201d Attack&#8221;<\/strong><\/p>\n<div>\n<figure style=\"width: 1200px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage size-full wp-image-747705\" data-pagespeed-lazy-srcset=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?width=398&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 400w, https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 1200w\" sizes=\"auto, 400w, 1200w\" data-pagespeed-lazy-src=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"Hacker with a laptop\" width=\"1200\" height=\"675\" src=\"\/pagespeed_static\/1.JiBnMqyl6S.gif\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/male-hacker-652144957\">ViChizh\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p>There\u2019s a vulnerability making the roundS for macOS called \u201cpowerdir\u201d that could lead to unauthorized access, which is precisely what most computer users would like to avoid. <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le fixed the vulnerability in macOS 11.6 and 12.1, but you need to update your devices to keep yourself safe.<\/p>\n<p>Interestingly, the vulnerability, which is called CVE-2021-30970, was detailed by the Microsoft\u00a0365 Defender Research Team in an intense\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=htg\/779399&amp;murl=https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2022%2F01%2F10%2Fnew-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access%2F\">blog post<\/a>. Microsoft alerted Apple\u00a0through the Coordinated Vulnerability Disclosure (CVD) via Microsoft Security Vulnerability Research (MSVR) on July 15, 2021. Apple then <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/support.apple.com\/en-us\/HT212978\">fixed<\/a> it on December 13, 2021.<\/p>\n<p>\u201cMicrosoft security researchers continue to monitor the threat landscape to discover new vulnerabilities and attacker techniques that could affect macOS and other non-Windows devices,\u201d said Microsoft.<\/p>\n<p>According to Apple\u2019s <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/support.apple.com\/en-us\/HT212978\">patch page<\/a>, \u201cA malicious application may be able to bypass Privacy preferences.\u201d To fix it, \u201cA logic issue was addressed with improved state management.\u201d<\/p>\n<p>The attack is designed to bypass the operating system\u2019s Transparency, Consent, and Control (TCC) <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">technology<\/a>, giving the attacker\u00a0unauthorized access to a user\u2019s protected data. This is far from the first\u00a0TCC vulnerability reported. In fact, the very same patch that fixed the one Microsoft discovered also addressed a few others.<\/p>\n<p>Based on the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=htg\/779399&amp;murl=https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2022%2F01%2F10%2Fnew-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access%2F\">technical details Microsoft shared<\/a>, specifically the mention that \u201cit is possible to programmatically change a target user\u2019s home directory and plant a fake TCC database, which stores the consent history of app requests,\u201d this attack must be performed locally. This means you\u2019d have to run specific software on your Mac for them to gain access, or they\u2019d need to actually be sitting in front of your computer.<\/p>\n<p>According to Microsoft, \u201cUsing this exploit, an attacker could change settings on any application.\u201d Microsoft also said that its exploit \u201callows the modification of settings to grant, for example, any app like Teams, to access the camera, among other services.\u201d<\/p>\n<p>If you\u2019ve already updated your Mac to the latest versions, you don\u2019t need to worry about this particular vulnerability (that doesn\u2019t mean new attacks won\u2019t pop up). If you\u2019re reluctant to update your Mac for one reason or another, let this major vulnerability serve as a reminder to keep your precious computer updated, as it\u2019s essential for your safety.<\/p>\n<\/div>\n<p><script>\n setTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s) } (window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n   fbq('init', '335401813750447');\n   fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.howtogeek.com\/779399\/psa-update-your-mac-to-avoid-the-powerdir-attack\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Update Your Mac to Avoid the \u201cpowerdir\u201d Attack&#8221; ViChizh\/Shutterstock.com There\u2019s a vulnerability making the roundS for macOS called \u201cpowerdir\u201d that could lead to unauthorized access, which is precisely what most computer users would like to avoid. Apple fixed the vulnerability in macOS 11.6 and 12.1, but you need to update your devices to keep yourself&#8230;<\/p>\n","protected":false},"author":1,"featured_media":393458,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?height=200p&trim=2,2,2,2","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-393457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/393457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=393457"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/393457\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/393458"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=393457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=393457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=393457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}