Multiple Microsoft Apps for macOS Vulnerable to Library Injection Attacks
ID: 14440788-1d56-5e6c-93b5-7563ee1ff9d9
STIX ID: report--14440788-1d56-5e6c-93b5-7563ee1ff9d9
Feed Name: Dark Reading
Cisco Talos researchers disclosed that several widely used Microsoft macOS apps disable library validation, permitting attackers with local/user-level access to inject malicious libraries that inherit app entitlements and bypass Apple's Transparency, Consent and Control (TCC) protections — potentially enabling covert use of camera, microphone, emailing, and other sensitive capabilities. Microsoft has applied updates to some apps but left Excel, Outlook, PowerPoint, and Word vulnerable and has described the issue as low-severity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
