Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    OnePlus 15’s First Update Just After Launch Day; Here’s What’s New

    November 14, 2025

    Apple’s new App Review Guidelines clamp down on apps sharing personal data with ‘third-party AI’

    November 14, 2025

    All Books Location (Building a Library) in Arc Raiders

    November 14, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Apple’s new App Review Guidelines clamp down on apps sharing personal data with ‘third-party AI’

      November 14, 2025

      Build Mode starts at the beginning: How Forethought AI found product-market fit

      November 14, 2025

      VCs abandon old rules for a ‘funky time’ of investing in AI startups

      November 14, 2025

      Blue Origin sticks first New Glenn rocket landing and launches NASA spacecraft

      November 14, 2025

      Uber quietly pilots in-app video recording for drivers in India

      November 14, 2025
    • Mobiles

      OnePlus 15’s First Update Just After Launch Day; Here’s What’s New

      November 14, 2025

      Vivo S50 Series Key Specifications Tipped: Expected to Launch in December

      November 14, 2025

      OPPO Introduces “LUMO Lab” Initiative to Elevate Mobile Photography in India

      November 14, 2025

      OnePlus 15 with Snapdragon 8 Elite Gen 5 SoC, 7300 mAh Battery, Android 16, 165Hz Display Launched in India

      November 14, 2025

      OPPO Reno15 Series India Launch Timeline and Price Range Leaked

      November 13, 2025
    • Gaming

      All Books Location (Building a Library) in Arc Raiders

      November 14, 2025

      Nintendo Switch 2 Update Has Bricked Some Docks

      November 14, 2025

      What Are T.E.D.D. Tasks in Black Ops 7 Zombies/

      November 14, 2025

      Best Manhwa With OP MCs

      November 13, 2025

      How to Start Kingdom Come Deliverance 2’s Mysteria Ecclesiae DLC

      November 13, 2025
    • SEO Tips
    • PC/ Laptops

      Apple Reportedly Reserving OLED Displays for M6 Pro and M6 Max MacBook Pro Models

      November 10, 2025

      Apple Reportedly Working on a Budget MacBook Featuring iPhone Chip: Expected Launch and Price

      November 5, 2025

      Acer Predator Helios Neo 16 AI and 16S AI Gaming Laptops Launched in India: Check Pricing and Specifications

      November 4, 2025

      COLORFUL Launches Rimbook L1: Affordable Laptop For Everyday Use

      November 4, 2025

      Acer Expands Lite Series With New Nitro Lite 16 Laptop in India

      November 3, 2025
    • EV

      GM’s President Explains What’s New

      November 14, 2025

      Teslas May Get Apple CarPlay Soon: Report

      November 14, 2025

      China Is Cracking Down On Too-Quick EVs

      November 14, 2025

      The Ford F-150 Lightning’s Struggles Are A Terrifying Lesson For The EV World

      November 13, 2025

      Breakthrough Device Promises To Cut Charging Times And Boost EV Range

      November 13, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Microsoft Office, Teams Vulnerabilities Enable Hackers to Access Camera and Microphone on macOS: Report
    Featured

    Microsoft Office, Teams Vulnerabilities Enable Hackers to Access Camera and Microphone on macOS: Report

    KavishBy KavishAugust 22, 2024No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Microsoft Office, Teams Vulnerabilities Enable Hackers to Access Camera and Microphone on macOS: Report
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    A cybersecurity group has discovered multiple vulnerabilities in apps developed by Microsoft for macOS that allowed hackers to target users. The security flaws affect apps such as Microsoft Office, Outlook, Teams, OneNote and other apps from the Redmond firm, and hackers were able to access a user’s camera and microphone by misusing Apple’s permission framework on its desktop operating system.. While Microsoft has issued fixes for two of its applications on macOS, its other apps are still vulnerable to attackers.

    Microsoft App Vulnerabilities Let Hackers Access Camera, Microphone Without Permissions

    Cybersecurity group Cisco Talos revealed details of eight vulnerabilities spotted in Microsoft’s apps for macOS in a blog post. These flaws allowed hackers to inject specially crafted malicious libraries into six Microsoft apps — Outlook, Teams, PowerPoint, Excel, Word, OneNote — and bypass Apple’s permission model on macOS.

    dylib injection cisco talos dylib injection

    How hackers can inject malicious libraries into legitimate apps on macOS
    Photo Credit: Cisco Talos

     

    In order to gain access to a user’s microphone and camera, malicious software would need to be granted explicit user consent for the relevant permissions, in accordance with Apple’s Transparency, Consent and Control (TCC) framework on macOS. However. some malicious programs can use a process called library injection (or dylib injection on macOS) to gain access to permissions that were granted to other apps.

    As a result, macOS users who had Microsoft’s apps installed on their computer could be vulnerable to hacking, according to Cisco Talos. The flaws allowed hackers to record audio by injecting libraries into the aforementioned apps. Microsoft Excel is the only app in the list that doesn’t have access to the microphone, while apps such as Microsoft Teams can also access the device’s camera.

    Microsoft Patches Two Affected Apps, Other Apps Remain Vulnerable

     The cybersecurity group says that it reported the security vulnerabilities to Microsoft, and the firm has since updated two of the affected apps with fixes for the flaws. Users who are running the latest versions of Microsoft Teams and OneNote should not be impacted, but the company’s Outlook and Office apps are currently affected by the security flaw.

    According to Cisco Talos, Microsoft should not have disabled library validation, as it exposes users to unnecessary risks by bypassing hardened runtime safeguards put in place by Apple on the OS, designed to protect users via TCC and its permission model.

    Apple could increase security on macOS by prompting users when a third-party plugin is being loaded into apps, as these apps might have already been granted permissions. This could warn users that these external plugins can access the same permissions granted to the original app. 



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    OnePlus 15’s First Update Just After Launch Day; Here’s What’s New

    November 14, 2025

    Apple’s new App Review Guidelines clamp down on apps sharing personal data with ‘third-party AI’

    November 14, 2025

    All Books Location (Building a Library) in Arc Raiders

    November 14, 2025

    GM’s President Explains What’s New

    November 14, 2025

    Build Mode starts at the beginning: How Forethought AI found product-market fit

    November 14, 2025

    Vivo S50 Series Key Specifications Tipped: Expected to Launch in December

    November 14, 2025

    Comments are closed.

    Top Reviews
    Editors Picks

    OnePlus 15’s First Update Just After Launch Day; Here’s What’s New

    November 14, 2025

    Apple’s new App Review Guidelines clamp down on apps sharing personal data with ‘third-party AI’

    November 14, 2025

    All Books Location (Building a Library) in Arc Raiders

    November 14, 2025

    GM’s President Explains What’s New

    November 14, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.