The Microsoft team discovered a vulnerability in macOS related to Spotlight. This vulnerability could allow attackers to steal private data from files using specially crafted Spotlight plugins. The threat team named this exploit "Sploitlight," as it leverages the capabilities of Spotlight plugins to bypass the Transparency, Consent, and Control (TCC) mechanism. This mechanism typically prevents applications from accessing personal information without user consent. However, Microsoft found a way to circumvent these restrictions by modifying the application packages that Spotlight pulls, leaking file contents and gaining access to sensitive information such as photo and video metadata, search history, facial recognition data from the photo library, and user settings.

Microsoft reported this issue to Apple, and the company quickly addressed it in the macOS 15.4 and iOS 15.4 updates released on March 31. The vulnerability was never actively exploited, as Apple managed to fix it before disclosure. In Apple's security support document, it is noted that the issue was resolved through improved data handling. Additionally, two other vulnerabilities were fixed, for which Microsoft is also thanked, including enhanced symbolic link verification and state management.
Comments
No comments
Add Comment