/>
X

Critical Mac QuickTime zero-day exploit released!

A zero-day Apple QuickTime flaw for Mac OS X has officially kicked off the MoAB (Month of Apple Bugs).  The exploit has been "100% reliable for a current up-to-date x86-based OS X system".
george-ou.jpg
Written by George Ou on

A zero-day Apple QuickTime flaw for Mac OS X has officially kicked off the MoAB (Month of Apple Bugs).  The exploit has been "100% reliable for a current up-to-date x86-based OS X system".  Anyone wishing to confirm the vulnerability in their own Intel-based Macs can click on this test link of a specially crafted QuickTime file that will say "happy new year" though the exploit can be easily modified to do more malicious things like delete all of your photos and documents or encrypt them for ransom.

This is the first of many Apple vulnerabilities that will be exposed this month.  This exploit is EXTREMELY dangerous because it can be remotely triggered with a malicious email attachment or a specially crafted webpage that will automatically trigger the QuickTime "movie" which is actually not a movie but a malicious payload.  The exploit is in weaponized Metasploit form and there are no patches available.  Disabling QuickTime playback in the web browser of choice might be the only temporary work-around at this time.  Mac users should also avoid opening QuickTime files they receive in email unless they're sure the file is from someone they trust and it's intended for them.

Related

He flew American Airlines, she flew United. For both, the unthinkable happened
screen-shot-2022-06-30-at-10-14-36-am.png

He flew American Airlines, she flew United. For both, the unthinkable happened

Business
Southwest Airlines has cancelled 20,000 flights. Now for the really bad news
screen-shot-2021-07-07-at-4-01-12-pm.png

Southwest Airlines has cancelled 20,000 flights. Now for the really bad news

Business
McDonald's and Chick-fil-A both have a big problem. Only one has a solution
screen-shot-2022-06-28-at-6-24-27-pm.png

McDonald's and Chick-fil-A both have a big problem. Only one has a solution

Business