Categories: Tech

A macOS vulnerability causes commands to be executed remotely

The cybersecurity researcher Park Minchan he discovered one still unresolved vulnerability in macOS, which allows hackers to execute commands remotely. The flaw creates problems for macOS Big Sur and earlier and can be very dangerous.

A macOS vulnerability puts Apple’s computers at risk

The problem concerns all shortcut files that contain the extension “inetloc”, which can hide commands to be executed remotely from the whole. Minchan explains: “A vulnerability in the way macOS process inetloc files causes the commands contained within to execute. The commands it executes can be internal to macOS, allowing the execution of arbitrary commands without any warning to the user. Inteloc commands were originally shortcuts [shortcut] to internet addresses, such as an RSS feed or a telnet location. And they contain the server address and possibly username and password for telnet or SSH connections. They can be simply created by typing a URL in a text editor and dragging the text onto the Desktop ”.

Minchan reported the flaw to Apple through the program SSD Secure Discolusure.

Internet shortcuts are present on both Windows and macOS. But this bug only affects the shortcuts of macOS users, especially those who use the native client for emails. In fact, by opening an e-mail attachment that contains an inetloc file, you risk activating the code inside, exploiting this flaw.

Apple would have fixed this problem blocking addresses in text files starting with “file: //“, Which allows you to activate a local shortcut. However Minchan pointed out that just writing File with a capital letter is enough to circumvent the fix.

So macOS users should be careful about opening any inteloc email attachments, especially if they are using the native client offered by Apple.

Published by
Walker Ronnie

Recent Posts

Inter-Turin: where to watch the match?

Football Sunday opens with the usual lunch match. Two teams that no longer have anything…

22 mins ago

Google Keep and Tasks integrate: Reminders synced across multiple apps

Google announced that over the next year i memorandum noted in Google Keep will finally…

2 hours ago

Eagle Pictures: Home Video releases for May 2024!

Through a press release, Eagle Pictures has revealed all the new home video releases in…

5 hours ago

F1, Ferrari: imminent announcement of the new title sponsor HP

The F1 Scuderia Ferrari will soon announce its new title sponsor, namely Hewlett-Packard (HP), which…

6 hours ago

FCC Restores Net Neutrality in US: What It Means for the Future of the Internet

The Federal Communications Commission (FCC) of the United States recently voted to reinstate the rules…

6 hours ago

eFootball: special promotions for 750 million downloads

Konami has announced that its popular football game, eFootballhas exceeded the extraordinary figure of 750…

6 hours ago