Google reveals “high severity” flaw in MacOS kernel

Google reveals “high severity” flaw in MacOS kernel

Google’s Project Zero team is well-known for its knack of finding security flaws in the company’s own products as well as those manufactured by other firms. A security researcher from Google’s Project Zero has discovered that even though macOS’ kernel, XNU, allows copy-on-write (COW) behavior in some cases, it is essential that any copied memory is not available for modifications from the source process. Project Zero has found out that if a user-owned mounted filesystem image is modified, the virtual management subsystem is not informed of the changes, which means that an attacker can potentially take malicious actions without the mounted filesystem knowing about it.

Source: www.neowin.net