MacOS Safari 'HM Surf' Exploit Exposes Camera, Mic, Browser Data
ID: 110e6186-1070-54a7-a536-f83f1876e3f5
STIX ID: report--110e6186-1070-54a7-a536-f83f1876e3f5
Feed Name: Dark Reading
Threat Score
A macOS Safari vulnerability (CVE-2024-44133), dubbed "HM Surf" by Microsoft, abuses Safari's com.apple.private.tcc.allow entitlement and a DSCL-based home-directory manipulation to bypass TCC protections and grant websites access to camera, microphone, location and browsing data; Microsoft observed activity resembling this method in use by AdLoad adware, Apple issued a Sequoia patch on Sept 16, and organizations are advised to update and monitor for detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
