Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Ethical hackers prove having a Mac doesn't make you immune to cyberattacks

A pair of security researchers have successfully hacked a Mac belonging to billionaire film producer Jeffrey Katzenberg — proving that owning a macOS device isn't an automatic defense against cyber threats.

Rachel Tobac, a social engineer and CEO of SocialProof Security, successfully carried out the attack on the unspecified macOS device. According to Tobac, the attack was a demonstration for identify theft protection firm Aura — a company that Katzenberg invests in.

Tobac leveraged a since-patched vulnerability and social engineering skills to get Katzenberg to click on a phishing link on a spoofed website. Once Katzenberg did so, she was able to steal photos, emails, and contacts from the Mac.

Additionally, the hacker was able to turn on the Mac's microphone and eavesdrop on Katzenberg without triggering the build-in macOS microphone indicator.

Tobac's husband Evan — also a hacker and security researcher — published another Twitter thread with details on the macOS vulnerability.

The exploit was built based on research from Ryan Pickren, who became notable when he was paid $100,500 for discovering a Safari Universal Cross-Site Scripting bug.

More specifically, the exploit leveraged the underlying bug to carry out an attack using iCloud links and Safari's sharing preferences. Importantly, the attack only worked because Katzenberg's Mac was out of date by several updates.

According to both Tobacs, some mitigations for the specific attack include keeping machines patched with the latest security updates, using at least two methods of verification for communications, and avoiding clicking on suspicious email links — particularly if they are sent in an urgent manner.



20 Comments

alexjenn 3 Years · 17 comments

So, what happen when someone uses an old Mac stuck with an old and unpatchable OS?

Wesley Hilliard 4 Years · 263 comments

alexjenn said:
So, what happen when someone uses an old Mac stuck with an old and unpatchable OS?

If you're on a device that old it is time to upgrade. macOS Monterey works on Macs released back to 2015. I think it is safe to say that's long enough.

jimh2 8 Years · 670 comments

Nothing says sketchy like "hacking" a computer owned by an owner of the company the hacker works for. Are we really supposed to believe this was not a setup to generate business. Assuming it was not a setup, I still would never advertise this as being done because it looks like a setup. In fact I would be embarrassed to publish this shameless attempt at demonstrating cred.

sflocal 16 Years · 6138 comments

"Hacking" is an overused and abused term.  No OS, regardless of the company is 100% secure.  This was a phishing attack.  There's a difference.

maltz 13 Years · 507 comments

Ethical hackers prove having a Mac doesn't make you immune to cyberattacks

Who said that it did? Mac antivirus has been around as long as Windows and even DOS antivirus. The ONLY people I've ever heard cite that claim are people trolling Apple users accusing the Apple users of believing it.