Privacy News Apple: Don't panic, but your Mac can be pwned via GarageBand .bands

Wingman

Level 4
Thread author
Verified
Well-known
Feb 6, 2017
154
Apple says a newly patched hole in its GarageBand music tool could allow for remote code execution on the Mac.

The GarageBand 10.1.6 update is being pushed out to all Macs running OS X Yosemite and later. Because GarageBand is installed by default on OS X systems, all Mac owners should install the patch, but those who regularly use the music composing software should pay particular attention.

The lone flaw addressed in the update, CVE-2017-2374, allows an attack to remotely execute simply by running a malformed .band file. Apple uses the .band format for all GarageBand project files.
 
  • Like
Reactions: vemn

Wingman

Level 4
Thread author
Verified
Well-known
Feb 6, 2017
154
For the members that have bigger network at home or mac at work, it appears that snort rules are already out for this (Snort Rules: 41350-41351)
 
  • Like
Reactions: vemn

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top