Security News > 2021 > January > Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security
Apple has removed a controversial feature from its macOS operating system that allowed the company's own first-party apps to bypass content filters, VPNs, and third-party firewalls.
Called "ContentFilterExclusionList," it included a list of as many as 50 Apple apps like iCloud, Maps, Music, FaceTime, HomeKit, the App Store, and its software update service that were routed through Network Extension Framework, effectively circumventing firewall protections.
The issue first came to light last October following the release of macOS Big Sur, prompting concerns from security researchers who said the feature was ripe for abuse, adding it could be leveraged by an attacker to exfiltrate sensitive data by piggybacking it on to legitimate Apple apps included on the list and then bypass firewalls and security software.
"After lots of bad press and lots of feedback/bug reports to Apple from developers such as myself, it seems wiser minds at Cupertino prevailed," said Patrick Wardle, a principal security researcher with Jamf, last week.
Researchers, including Wardle, found last year that Apple's apps were being excluded from NEFilterDataProvider, a network content filter that makes it possible for firewall and VPN apps such as LuLu and Little Snitch to monitor and control data traffic from installed apps on the system.
Wardle demonstrated an instance of how malicious apps could exploit this firewall bypass to transmit data to an attacker-controlled server using a simple Python script that latched the traffic onto an Apple exempted app despite setting LuLu and Little Snitch to block all outgoing connections on a Mac running Big Sur.
News URL
http://feedproxy.google.com/~r/TheHackersNews/~3/Eu6wIQHUeXw/apple-removes-macos-feature-that.html
Related news
- North Korean hackers create Flutter apps to bypass macOS security (source)
- Apple fixes 2 zero-days exploited to breach macOS systems (CVE-2024-44309, CVE-2024-44308) (source)
- Phishers send corrupted documents to bypass email security (source)
- Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS (source)