logo

macOS HM Surf vuln might already be under exploit by major malware family

ID: a09238c4-746c-5eff-b41c-7f36352e2024

STIX ID: report--a09238c4-746c-5eff-b41c-7f36352e2024

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-10-21

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Microsoft disclosed a Safari-related macOS vulnerability (CVE-2024-44133) that allows attackers to tamper with local configuration files to bypass TCC privacy protections; the company developed a PoC exploit called "HM Surf," deployed detections, and observed activity resembling the Adloader macOS malware, while Apple issued a patch in macOS Sequoia to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.