Microsoft discovers macOS vulnerability that could expose your data — what we know

macOS Sonoma desktop on MacBook Pro 14 inch
(Image credit: Future)

Microsoft recently revealed details about a security flaw in the macOS that affected the Transparency, Consent, and Control framework, which could be exploited to sidestep your privacy preferences and access data within the Safari browser. 

Detailed in a Microsoft Threat Intelligence blog post, the flaw was known as CVE-2024-44133 but given the Pokemon-esque codename HM Surf by the Microsoft team. The flaw has been patched by Apple in a macOS Sequoia 15 update, where the company wrote that the issue was resolved by "removing the vulnerable code." 

According to Microsoft's Jonathan Bar Or, HM Surf "involves removing the TCC protection for the Safari browser directory and modifying a configuration file in the said directory to gain access to the user's data, including browsed pages, the device's camera, microphone, and location, without the user's consent."

Microsoft wrote in the post that the Sequoia 15 update only protects Apple's Safari browser. However, it was noted that browsers like Google Chrome and Mozilla Firefox "do not have the same private entitlements as Apple applications," so they can't bypass the TCC checks. That means that once people approve TCC checks, it is up to the app to maintain access to the privacy database.

TCC works by preventing apps from accessing your personal data or browser history. The since-patched vulnerability would allow bad actors to get around the TCC check and access a multitude of data, including your camera, microphone, downloads director and others.    

Microsoft explained how they got to the exploit: 

  • Change the home directory of the current user with the dscl utility, which does not require TCC access in Sonoma (At this point, the ~/Library/Safari directory is no longer TCC protected).
  • Modify the sensitive files under the user’s real home directory (such as /Users/$USER/Library/Safari/PerSitePreferences.db).
  • Change the home directory again so Safari uses the now modified files.
  • Run Safari to open a webpage that takes a camera snapshot and trace device location.

HM Surf is the latest in several Apple macOS flaws discovered by Microsoft, including Achilles, Migraine, powerdir and Shrootless, that potentially allow bad actors to get around security checks.

The blog post also noted suspicious activity with a macOS adware threat called AdLoad that exploits the flaw.

"Since we weren't able to observe the steps taken leading to the activity, we can't fully determine if the AdLoad campaign is exploiting the HM surf vulnerability itself," Bar Or wrote. "Attackers using a similar method to deploy a prevalent threat raises the importance of having protection against attacks using this technique."

You should update to the latest security patch as soon as possible.

More from Tom's Guide

TOPICS
Scott Younker
West Coast Reporter

Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the lastest tech news. He’s been involved in tech since 2011 at various outlets and is on an ongoing hunt to build the easiest to use home media system. When not writing about the latest devices, you are more than welcome to discuss board games or disc golf with him. 

Read more
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop.
Mac and iPhone users beware — Apple processors can be exploited to steal sensitive information
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
MacBook Pro 2021 (16-inch) on a patio table
Macs under attack from dangerous malware targeting digital wallets and Apple’s Notes app — how to stay safe
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
OnePlus 13 back, leaning against blue wall
OnePlus 13T could come with an even bigger battery than OnePlus 13 — this is incredible
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
Titus Welliver in Bosch Legacy season 3
‘Bosch’ season 3 preview: 5 things to know before the final season on Prime Video
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on