Friday, November 22, 2024

Microsoft Office, Teams Vulnerabilities Enable Hackers to Access Camera and Microphone on macOS: Report

Date:

Share post:


A cybersecurity group has discovered multiple vulnerabilities in apps developed by Microsoft for macOS that allowed hackers to target users. The security flaws affect apps such as Microsoft Office, Outlook, Teams, OneNote and other apps from the Redmond firm, and hackers were able to access a user’s camera and microphone by misusing Apple’s permission framework on its desktop operating system.. While Microsoft has issued fixes for two of its applications on macOS, its other apps are still vulnerable to attackers.

Microsoft App Vulnerabilities Let Hackers Access Camera, Microphone Without Permissions

Cybersecurity group Cisco Talos revealed details of eight vulnerabilities spotted in Microsoft’s apps for macOS in a blog post. These flaws allowed hackers to inject specially crafted malicious libraries into six Microsoft apps — Outlook, Teams, PowerPoint, Excel, Word, OneNote — and bypass Apple’s permission model on macOS.

dylib injection cisco talos dylib injection

How hackers can inject malicious libraries into legitimate apps on macOS
Photo Credit: Cisco Talos

 

In order to gain access to a user’s microphone and camera, malicious software would need to be granted explicit user consent for the relevant permissions, in accordance with Apple’s Transparency, Consent and Control (TCC) framework on macOS. However. some malicious programs can use a process called library injection (or dylib injection on macOS) to gain access to permissions that were granted to other apps.

As a result, macOS users who had Microsoft’s apps installed on their computer could be vulnerable to hacking, according to Cisco Talos. The flaws allowed hackers to record audio by injecting libraries into the aforementioned apps. Microsoft Excel is the only app in the list that doesn’t have access to the microphone, while apps such as Microsoft Teams can also access the device’s camera.

Microsoft Patches Two Affected Apps, Other Apps Remain Vulnerable

 The cybersecurity group says that it reported the security vulnerabilities to Microsoft, and the firm has since updated two of the affected apps with fixes for the flaws. Users who are running the latest versions of Microsoft Teams and OneNote should not be impacted, but the company’s Outlook and Office apps are currently affected by the security flaw.

According to Cisco Talos, Microsoft should not have disabled library validation, as it exposes users to unnecessary risks by bypassing hardened runtime safeguards put in place by Apple on the OS, designed to protect users via TCC and its permission model.

Apple could increase security on macOS by prompting users when a third-party plugin is being loaded into apps, as these apps might have already been granted permissions. This could warn users that these external plugins can access the same permissions granted to the original app. 


LEAVE A REPLY

Please enter your comment!
Please enter your name here

spot_img

Related articles

Samsung’s One UI 7 Update Release Timeline for Galaxy S24 Series and Older Models Leaked

One UI 7 — Samsung's upcoming Android 15-based software update for eligible smartphones — is expected to...

Samsung Galaxy Book4 Series Offer Ultimate Performance for Both Creators and Professionals

Samsung has finally introduced its next-generation ultra-modern notebooks for the Indian market with the launch of its...

Vinta Nanda slams Imtiaz Ali`s statement at IFFI 2024 on women safety

Veteran television producer Vinta Nanda, who was among the first women to break their silence and amplify...

Xiaomi 15 Allegedly Listed on BIS Website, India Launch Expected Soon

Xiaomi 15 and Xiaomi 15 Pro have been on sale in China since the end of October, and they...