121 posts tagged ‘macOS 14 Sonoma’
SysBumps Attack
Guru Baran (via Ric Ford, PDF): The research team from Korea University, led by Hyerean Jang, Taehun Kim, and Youngjoo Shin, presented their findings in a paper titled “SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple Silicon.” Their work represents the first successful KASLR break attack on macOS systems […]
macOS 14.7.2 and macOS 13.7.2
Apple (release notes, full installer): This document describes the security content of macOS Sonoma 14.7.2. Apple (release notes, full installer): This document describes the security content of macOS Ventura 13.7.2. See also: Howard Oakley. Previously: macOS 14.7.1 and macOS 13.7.1
High Power Mode for M4 Pro Macs
Andrew Cunningham: Last year’s M3 Pro chip was a departure from the M1 Pro and M2 Pro. Compared to the M2 Pro, it came with more E-cores but fewer P-cores, as well as fewer GPU cores and less memory bandwidth. As we wrote at the time, this meant that the architectural improvements to M3 mostly […]
macOS 14.7.1 and macOS 13.7.1
Apple (release notes, full installer): This document describes the security content of macOS Sonoma 14.7.1. Apple (release notes, full installer): This document describes the security content of macOS Ventura 13.7.1. See also: Howard Oakley. Previously: macOS 14.7 and macOS 13.7
Qbix Calendar Apps and the Mac App Store
A reader shared a story about the confusing and unfortunate situation with Qbix’s calendar apps on the Mac App Store. There are two separate apps: Calendars (which used to be called Calendar 2, previously discussed) and Calendar Plus. Calendar Plus hasn’t been updated in 10 years but is still for sale as a $9.99 up-front […]
Time Machine in Sequoia
Der Teilweise: Backing up to a NAS currently says 3 days (!) left, after having backed up ~160GB. Was using WiFi with TX rate 133MBit. Now I connected using Gigabit Ethernet, does not seem to be faster. Plus: CPU usage is ridiculously high, fans spinning up to medium/max speed several times per hour. […] I […]
TCC and Gatekeeper Bypasses
Wojciech Reguła (September 2021, tweet): I was looking for code injection opportunities that may allow reaching TCC bypasses. My simple shell script discovered a potential victim - /System/Library/CoreServices/Applications/Directory Utility.app. It had (and has) the following private TCC entitlement[…] This entitlement allows the Directory Utility to modify the user’s records stored in the /var/db/dslocal/nodes directory. […] […]
Prompt 3
Panic (Mastodon): When you buy Prompt, you’ll get both the mobile and desktop apps.[…]MOSH & ETERNAL TERMINAL. Use these two new connection types for mega-stable terminals even if your network connection is garbageQuickly insert your most frequently used commands and text snippets with a tap or a click.[…]Easily sync your servers, keys and passwords between […]