Categories: News

Here’s some updates on some Mac-related vulnerabilities

A stored cross-site scripting (XSS) vulnerability in the iCloud domain has reportedly been patched by Apple, per a blog post shared by ZDNet.

The post says that bug bounty hunter and penetration tester Vishal Bharad claims to have discovered the security flaw, which is a stored XSS issue in icloud.com. According to Bharad, the XSS flaw in icloud.com was found in the Page/Keynotes features of Apple’s iCloud domain.

ZDNet says it’s reached out to Apple for comment and “will update when we hear back.”

Speaking of vulnerabilities, MacRumors reported on the second known piece of malware compiled to run natively on M1 Macs. Dubbed “Silver Sparrow,” the malicious package is said to leverage the macOS Installer JavaScript API [application programming interfaces] to execute suspicious commands. 

After observing the malware for over a week, however, security firm Red Canary did not observe any final payload, so the exact threat to users remains a mystery. Apple has since informed MacRumors that it has revoked the certificates of the developer accounts used to sign the packages, preventing additional Macs from being infected. Apple also reiterated that Red Canary found no evidence to suggest the malware has delivered a malicious payload to Macs that have already been infected.

Dennis Sellers

Dennis Sellers is the editor/publisher of Apple World Today. He’s been an “Apple journalist” since 1995 (starting with the first big Apple news site, MacCentral). He loves to read, run, play sports, and watch movies.

Recent Posts

Apple Store retail employees in New Jersey Vote Against Unionizing

According to Bloomberg, Apple retail employees in New Jersey have voted against unionization, the Communications…

5 hours ago

Workers at Apple’s Towson, Maryland, retail store will go on strike

Workers at Apple’s retail store in Towson, Maryland, have voted in favor of authorizing a…

9 hours ago

Apple: No Major App Developers Accept New Outside Payments

No major app developers have signed up to use outside payment options that Apple introduced…

9 hours ago

Apple reportedly close to an agreement to use OpenAI in its artificial intelligence push

Apple has closed in on an agreement with OpenAI to use the startup’s technology on…

1 day ago

Top Apple-related stories this week (May 6-10)

Here are the top Apple-related articles at Apple World Today for the week of May…

1 day ago

Comparison of Outsourcing Opportunities of Poland and Romania

The fast-paced global economy sees outsourcing as a cornerstone strategy for businesses striving to streamline…

1 day ago