logo

New macOS vulnerability, “HM Surf”, could lead to unauthorized data access

ID: f2c46433-c8f6-5855-82ce-0d3d14bde308

STIX ID: report--f2c46433-c8f6-5855-82ce-0d3d14bde308

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2024-10-17

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence disclosed HM Surf (CVE-2024-44133), a macOS vulnerability that removes TCC protections for the ~/Library/Safari directory enabling attackers to modify Safari configuration (PerSitePreferences.db) and cause Safari to grant camera, microphone, location, and browsing-data access without user consent; Apple released a patch in macOS Sequoia and Microsoft Defender for Endpoint detects and blocks exploitation attempts, with telemetry showing Adload-related activity that modified browser preference files using a world-writable temporary binary and a fake com.BasicIndex.service installation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.