macOS Mojave Bug Bypasses System Security


Security researcher Patrick Wardle has uncovered a macOS Mojave bug. It is currently found on all Macs running macOS Mojave and allows unauthorized access to your personal data.

[Top 6 Free Mac Security Tools]

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

macOS Mojave Bug

Mr. Wardle announced the bug on Twitter and showed how he could bypass Mojave’s privacy protections. Any app could take advantage of the bug and gain access to sensitive information.

In the short video he provided, Mr. Wardle types commands into Terminal. First he opens the Address Book and clicks the Don’t Allow button to prevent access. Then he uses his app that exploits the bug and this lets him copy the entire address book to the desktop.

This is considered a zero day vulnerability since Mojave was just released to the public on September 24. Apple has yet to make a public comment regarding the bug, but will certainly patch it in a future update.

[Mac Adware Tool Sends Your Data to China]

Discussion

2 comments
Newest first
Join the discussionCommenting as a guest — your email is never published · Log in

Protected by Akismet — be kind, stay on topic.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  1. Lee Dronick Subscriber 8 years ago

    So it needs someone with physical access to your Mac?

    Reply
    1. Andrew Orr Author 8 years ago

      It sounds like it could be remote

      Reply