• Home
  • Politics
  • News
  • Business
  • Health
  • Entertainment
  • Sports
  • Lifestyle
  • Education
  • Opinion
Sunday, 16 November, 2025
  • Login
Top Radio 103.1 FM
 
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Health
  • Lifestyle
  • Sports
  • Education
  • Technology
  • Foreign
No Result
View All Result
Top Radio 103.1 FM
No Result
View All Result
Home Technology

Microsoft releases tweet-size exploit for macOS sandbox escape bug

TOPFM NEWS by TOPFM NEWS
July 14, 2022
in Technology
A A
0
Microsoft releases tweet-size exploit for macOS sandbox escape bug
0
SHARES
16
VIEWS
Share on FacebookShare on Twitter

Microsoft has published the exploit code for a vulnerability in macOS that could help an attacker bypass sandbox restrictions and run code on the system.

The company released the technical details for the security issue, which is currently identified as CVE-2022-26706, and explained how the macOS App Sandbox rules could be avoided to allow malicious macro code in Word documents to execute commands on the machine.

Abusing macros in Office documents to deploy malware has long been an efficient and popular technique to compromise Windows systems.

The same could be achieved on macOS machines lacking the proper security updates, Microsoft warns in a report today.

“Despite the security restrictions imposed by the App Sandbox’s rules on applications, it’s possible for attackers to bypass the said rules and let malicious codes “escape” the sandbox and execute arbitrary commands on an affected device” – Microsoft

Jonathan Bar Or of the Microsoft 365 Defender Research Team explains that the vulnerability was discovered while looking into methods to run and detect malicious macros in Microsoft Office documents on macOS.

To ensure backward compatibility, Microsoft Word can read and write files that come with the prefix “~$,” which is defined in the app’s sandbox rules.

Sandbox rule for Microsoft Word on macOS
Sandbox rule for Microsoft Word on macOS
source: Microsoft

Exploit code in a tweet

After studying older reports [1, 2] about escaping the macOS sandbox, the researchers found that using Launch Services to run an open –stdin command on a special Python file with the abovementioned prefix allows escaping the App Sandbox on macOS, potentially leading to compromising the system.

The researchers came up with a proof-of-concept (PoC) that used the -stdin option for the open Command on a Python file to bypass the “com.apple.quarantine” extended attribute restriction.

The demo exploit code is as simple as dropping a Python file that contains arbitrary commands and has in its name the special prefix for Word.

Using the open -stdin command starts the Python app with the specially crafted file as the standard input.

“Python happily runs our code, and since it’s a child process of launchd, it isn’t bound to Word’s sandbox rules,” Jonathan Or Bar explains.

Microsoft's exploit for escaping the macOS sandbox
macOS sandbox escape PoC
source: Microsoft

The researchers even managed to compress the exploit code above so much that it fits into a tweet.

Tweet-size exploit for escaping the macOS sandbox
Tweet-size version of macOS sandbox escape PoC​​​​​
source: Microsoft

Microsoft reported the vulnerability to Apple last year in October and a fix was delivered with the macOS security updates in May 2022 (Big Sur 11.6.6)

Credit for responsibly disclosing the issue is shared with another security researcher, Arsenii Kostromin, who found it independently.

Related Posts

Toyota global production down for 10th month despite rising sales

Toyota global production down for 10th month despite rising sales

December 26, 2024 - Updated on December 28, 2024
62
Ghana leads four other African countries to sign SATA declaration on data and digital identity interoperability

Ghana leads four other African countries to sign SATA declaration on data and digital identity interoperability

April 27, 2023
9
Source: Ionut Ilascu
Via: bleepingcomputer
Tags: Microsoft releases tweet-size exploit for macOS sandbox escape bug
Previous Post

Final Android 13 beta arrives ahead of its official launch ‘in the weeks ahead’

Next Post

US, Israel to commit to stopping Iran nuclear ambitions

Related Posts

Toyota global production down for 10th month despite rising sales
News

Toyota global production down for 10th month despite rising sales

December 26, 2024 - Updated on December 28, 2024
62
Ghana leads four other African countries to sign SATA declaration on data and digital identity interoperability
Technology

Ghana leads four other African countries to sign SATA declaration on data and digital identity interoperability

April 27, 2023
9
TikTok launches an elections hub in Kenya ahead of General Elections
Technology

TikTok launches an elections hub in Kenya ahead of General Elections

July 15, 2022
16
Facebook to allow up to five profiles tied to one account
Technology

Facebook to allow up to five profiles tied to one account

July 15, 2022
16
Final Android 13 beta arrives ahead of its official launch ‘in the weeks ahead’
Technology

Final Android 13 beta arrives ahead of its official launch ‘in the weeks ahead’

July 14, 2022
11
Ex-CIA engineer Joshua Schulte convicted over massive data leak
Technology

Ex-CIA engineer Joshua Schulte convicted over massive data leak

July 14, 2022
11
Next Post
US, Israel to commit to stopping Iran nuclear ambitions

US, Israel to commit to stopping Iran nuclear ambitions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

BROWSE BY CATEGORIES

  • Business
  • Education
  • Entertainment
  • Foreign
  • Health
  • Lifestyle
  • News
  • Opinion
  • Politics
  • Sports
  • Technology
  • Uncategorized

BROWSE BY TOPICS

2022 Budget AFCON Afghanistan akufo addo Amazon Apiate explosion apple AT&T Ato Forson Black Stars covid COVID-19 E-Levy facebook galamsey Ghana Police Service Google Government GRA health Highlife Intel iphone LGBTQ Mahama Majority Microsoft Minority momo NDC NPP Nvidia OMICRON Parliament police Russia security South Africa Taliban tech Tesla US UTAG vaccine Xinjiang

Recent Posts

  • Lydia Forson calls on authorities to stop rising pedophilia cases; urges victims to report abusers
  • English football icon David Beckham knighted by King Charles at Windsor Castle
  • I charge for every performance even including my friends and people I know – Obaapa Christy
  • I suffered for 10 years: Samini opens up about hiding hernia from public
  • Police arrests 4; seize 2,250 parcels of ‘weed’ at KEEA

Recent Comments

  1. meinestadtkleinanzeigen.de on (Photos) GNFS Suppress Fire At Lakeside Estate Apartment
  2. News on Church Of Pentecost Commission 35 Bed AI Powered Hospital In Bolgatanga (Photos)

RECENT NEWS

  • Lydia Forson calls on authorities to stop rising pedophilia cases; urges victims to report abusers November 6, 2025
  • English football icon David Beckham knighted by King Charles at Windsor Castle November 4, 2025
  • I charge for every performance even including my friends and people I know – Obaapa Christy November 3, 2025
  • I suffered for 10 years: Samini opens up about hiding hernia from public October 22, 2025

MAIN CATEGORIES

  • Business
  • Education
  • Entertainment
  • Foreign
  • Health
  • Lifestyle
  • News
  • Opinion
  • Politics
  • Sports
  • Technology
  • Uncategorized

Entertainment

Treating Mpox In Ghana: With What? Dr Mintah Bonku Writes
Health

Treating Mpox In Ghana: With What? Dr Mintah Bonku Writes

5 months ago
52
  • ABOUT US
  • CONTACT
  • ADVERTISE

© 2025 Top Media Group - Powered by BackUP Data Systems

No Result
View All Result
  • Home
  • Politics
  • News
  • Business
  • Health
  • Entertainment
  • Sports
  • Lifestyle
  • Education
  • Opinion

© 2025 Top Media Group - Powered by BackUP Data Systems

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In