Close Menu
    Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn TikTok
    TopBuzzMagazine.com
    Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn TikTok
    • Home
    • Movies
    • Television
    • Music
    • Fashion
    • Books
    • Science
    • Technology
    • Cover Story
    • Contact
      • About
      • Amazon Disclaimer
      • Terms and Conditions
      • Privacy Policy
      • DMCA / Copyrights Disclaimer
    TopBuzzMagazine.com
    Home»Technology»A Bug in Apple MacOS Ventura Breaks Third-Party Security Tools
    Technology

    A Bug in Apple MacOS Ventura Breaks Third-Party Security Tools

    By AdminNovember 3, 2022
    Facebook Twitter Pinterest LinkedIn Tumblr Email

    Apple attempted to fix the flaw multiple times throughout 2022, but each time, Fitzl says, he was able to find a workaround for the company’s patch. Finally, Apple took a bigger step in Ventura and made more comprehensive changes to how it manages the permission for security services. In doing that, though, the company made a different mistake that’s now causing the current issues.

    “Apple fixed it, and then I bypassed the fix, so they fixed it again, and I bypassed it again,” Fitzl says. “We went back and forth like three times, and eventually they decided that they will redesign the whole concept, which I think was the right thing to do. But it was a bit unfortunate that it came out in the Ventura beta so close to the public release, just two weeks before. There wasn’t time to be aware of the issue. It just happened.”

    If you use a security scanner on your Mac and you update to macOS Ventura, check the program directly to see if it’s flagging an error. The workaround to fix the problem is simple once you know to do it. In System Preferences go to Security & Privacy, then the Privacy tab, and then Full Disk Access. Click the lock icon in the lower-left corner of the screen and authenticate with your system password to allow changes. Then uncheck the box next to any security services that are malfunctioning, to let the system know you want to disable their permission. Click the lock in the lower-left corner again to save the change, then redo the process and recheck the relevant boxes to freshly enable the permission without the flaw.

    “Once you upgrade to Ventura, you could run a Malwarebytes scan, but it wouldn’t scan everything that it could if it had full disk access, and all of the real-time protection features are completely disabled,” Malwarebytes’ Reed says. “We get handicapped if we don’t get full disk access. And there are a number of ways that you could tell if Malwarebytes is not functioning properly, but if you’re not looking in the right places or you disabled certain settings, you might not notice. With other security clients, it’s probably similar—if you’re not interacting with it, you might not know.”

    Researchers noticed—and Apple confirmed to WIRED—that the bug doesn’t happen when large organizations use Apple’s “mobile device management” program to upgrade their fleet of devices to Ventura. This is significant, because if the bug carried over to managed enterprise devices, it would mean yet another reason for companies to put off important software updates. 

    MacOS security researcher Patrick Wardle, founder of the Objective-See Foundation, says that he still recommends regular users upgrade their Macs to Ventura to get the new operating system’s other security and privacy protections. In the meantime, though, Wardle says he has been deluged by bug reports about his free, open source malware monitoring tool, BlockBlock. The Ventura bug even makes it appear that security services like BlockBlock and Malwarebytes have been granted extra system access beyond what these programs request, including the accessibility permission, access to input monitoring, and even screen recording. 

    “Users were understandably asking me, ‘Why does your tool need that?!’ And I’m like, ‘Uh, I have no idea. It doesn’t!’” Wardle says. “It shows that when Apple is pushing out security fixes for reported bugs, they’re still struggling to do that comprehensively and successfully without breaking other things. And in this case, they’re shipping a version of their operating system that is breaking security tools for millions, if not tens of millions, of users. It’s frustrating and disheartening.”

    Independent researcher Fitzl, who presented his original disabling permission vulnerability findings at Black Hat Asia in May and Wardle’s Objective-See Mac and iOS security conference at the beginning of October, says that he’s sympathetic about the misstep. 

    “Apple was trying to redesign this thing to fix all of my bypasses, and they made a mistake—it happens,” he says. But he adds, ruefully, that the whole situation has played out in an unfortunate way. “I felt a bit weird about all of these issues and knowing that I pushed Apple into this because I was trying to get something else fixed.”

    Read The Full Article Here

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Bhutan Partners With Binance to Launch Crypto Payment System for Tourists

    May 8, 2025

    Birdfy Nest Polygon Smart Birdhouse Review: Primed for Pictures

    May 7, 2025

    An AWS survey of 3,739 senior IT decision-makers across nine countries finds 45% plan to prioritize spending on generative AI in 2025, and 30% on cybersecurity (Todd Bishop/GeekWire)

    May 7, 2025

    Google Might Be Working On Connecting Apps With Gemini Live: Report

    May 6, 2025

    OpenAI Backs Down on Restructuring Amid Pushback

    May 6, 2025

    Researchers: open source serialization tool easyjson, developed by Russia's VK Group and widely used by the US DOD and others, poses a national security risk (Matt Burgess/Wired)

    May 5, 2025
    popular posts

    Researchers create salts for cheap and efficient CO2 capture

    Brand New Business Books to Wake Up Leaders Everywhere

    Biologists examine low-cost ways to improve urban streams

    A Man Called Otto review – Tom Hanks stars in

    AuthorBuzz: The Only Crime Novel Lucinda Riley Ever Wrote

    Watch La Brea Online: Season 2 Episode 8

    The Nightmare Politics and Sticky Science of Hacking the Climate

    Categories
    • Books (3,211)
    • Cover Story (2)
    • Events (18)
    • Fashion (2,380)
    • Interviews (41)
    • Movies (2,510)
    • Music (2,788)
    • News (153)
    • Science (4,361)
    • Technology (2,502)
    • Television (3,233)
    • Uncategorized (932)
    Archives
    Facebook X (Twitter) Instagram Pinterest YouTube Reddit TikTok
    © 2025 Top Buzz Magazine. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms of Use and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
    Do not sell my personal information.
    Cookie SettingsAccept
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT