• Home
  • Laptops
  • Laptops News
  • Microsoft Office, Teams Vulnerabilities Enable Hackers to Access Camera and Microphone on macOS: Report

Microsoft Office, Teams Vulnerabilities Enable Hackers to Access Camera and Microphone on macOS: Report h6e6p

Microsoft has patched two out of eight applications on macOS, while other affected apps remain vulnerable to the security flaw. 4n5a4p

Microsoft Office, Teams Vulnerabilities Enable Hackers to Access Camera and Microphone on macOS: Report

Photo Credit: Microsoft 4c1m61

Microsoft Outlook is one of the company's applications affected by the flaws on macOS

Highlights
  • Microsoft apps including Teams, OneNote vulnerable to library injection
  • Hackers can use this to access permissions granted to legitimate apps
  • Microsoft is yet to issue fixes for the vulnerabilities on some apps
ment

A cybersecurity group has discovered multiple vulnerabilities in apps developed by macOS that allowed hackers to target s. The security flaws affect apps such as Microsoft Office, Outlook, Teams, OneNote and other apps from the Redmond firm, and hackers were able to access a 's camera and microphone by misusing Apple's permission framework on its desktop operating system.. While Microsoft has issued fixes for two of its applications on macOS, its other apps are still vulnerable to attackers.

Microsoft App Vulnerabilities Let Hackers Access Camera, Microphone Without Permissions 2646r

Cybersecurity group Cisco Talos revealed details of eight vulnerabilities spotted in Microsoft's apps for macOS in a OneNote — and by Apple's permission model on macOS.

dylib injection cisco talos dylib injection

How hackers can inject malicious libraries into legitimate apps on macOS
Photo Credit: Cisco Talos

 

In order to gain access to a 's microphone and camera, malicious software would need to be granted explicit consent for the relevant permissions, in accordance with Apple's Transparency, Consent and Control (TCC) framework on macOS. However. some malicious programs can use a process called library injection (or dylib injection on macOS) to gain access to permissions that were granted to other apps.

As a result, macOS s who had Microsoft's apps installed on their computer could be vulnerable to hacking, according to Cisco Talos. The flaws allowed hackers to record audio by injecting libraries into the aforementioned apps. Microsoft Excel is the only app in the list that doesn't have access to the microphone, while apps such as Microsoft Teams can also access the device's camera.

Microsoft Patches Two Affected Apps, Other Apps Remain Vulnerable 6w1h8

 The cybersecurity group says that it reported the security vulnerabilities to Microsoft, and the firm has since updated two of the affected apps with fixes for the flaws. s who are running the latest versions of Microsoft Teams and OneNote should not be impacted, but the company's Outlook and Office apps are currently affected by the security flaw.

According to Cisco Talos, Microsoft should not have disabled library validation, as it exposes s to unnecessary risks by bying hardened runtime safeguards put in place by Apple on the OS, designed to protect s via TCC and its permission model.

Apple could increase security on macOS by prompting s when a third-party plugin is being loaded into apps, as these apps might have already been granted permissions. This could warn s that these external plugins can access the same permissions granted to the original app. 

Comments

For the latest reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Apple
David Delima
As a writer on technology with Gadgets 360, David Delima is interested in open-source technology, cybersecurity, consumer privacy, and loves to read and write about how the Internet works. David can be ed via email at [email protected], on Twitter at @DxDavey, and Mastodon at mstdn.social/@delima. More
GoPro to Cut 15 Percent of Workforce in Restructuring Push
iQOO Neo 10, Neo 10 Pro Tipped to Feature Metal Frame, 100W Fast Charging, More
Facebook Gadgets360 Twitter Share Tweet Snapchat LinkedIn Reddit Comment google-newsGoogle News

ment

Follow Us

ment

© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »