Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

macOS 11.3 patches bug that allowed attacks to bypass Mac security

Apple in macOS Big Sur 11.3 fixed a bug that could have allowed attackers to bypass the Mac's security mechanisms with a malicious document.

The software flaw allowed attackers to create a malicious application that could masquerade as a document, TechCrunch reported Monday. Security researcher Cedric Owens first discovered the bug in March.

According to Owens, "all the user would need to do is double click — and no macOS prompts or warnings are generated." The researcher created a proof-of-concept app that exploited the flaw to launch the Calculator app.

Although Owens' demonstration app was harmless, a malicious attacker could have leveraged the vulnerability to remotely access sensitive data or other information on a user's machine by tricking them into clicking a spoofed document.

Security researcher and Mac specialist Patrick Wardle also reported that the bug is being actively exploited in the wild as a zero-day vulnerability. He added that the flaw was caused by a logic issue in macOS's code.

Apple told TechCrunch that it patched the bug in macOS Big Sur 11.3, which the Cupertino tech giant released on Monday. In addition to that release, Apple also issued patches for the flaw to macOS Catalina and macOS Mojave.

In addition to patching the specific vulnerability, Apple's macOS Big Sur 11.3 update also includes fixes for a bevy of other security flaws.

macOS Big Sur 11.3 should now be available as an over-the-air update to all users on compatible Macs.



4 Comments

lkrupp 19 Years · 10521 comments

Security updates for Mojave and Catalina also released patching the same issues.

AppleMac@76 5 Years · 7 comments

Does anyone know if YouTube is compatible with M1? I know this article is not about that. The article I was trying to post in had the thread discontinued. 

nicholfd 6 Years · 828 comments

Does anyone know if YouTube is compatible with M1? I know this article is not about that. The article I was trying to post in had the thread discontinued. 

Youtube web site works just fine on an M1.  Who needs an app for YouTube?

Rayz2016 8 Years · 6957 comments

lkrupp said:
Security updates for Mojave and Catalina also released patching the same issues.

But … but … built-in obselence!