Microsoft Discloses Critical 'Sploitlight' Flaw in macOS
Microsoft Threat Intelligence researchers have detailed Sploitlight, a vulnerability in Spotlight's indexing service (CVE-2025-31199) that enables attackers to circumvent macOS's Transparency, Consent, and Control (TCC) framework. By planting a malicious .mdimporter plugin in a user's Library folder, adversaries can exfiltrate files from protected directories and extract sensitive Apple Intelligence caches—such as precise geolocation data, photo metadata and search history—without triggering any user consent prompts.
Apple addressed the issue with a security update for macOS Sequoia on March 31, 2025, following a coordinated disclosure. Microsoft notes that Defender for Endpoint has been updated to detect anomalous plugin installations and unusual Spotlight indexing, reinforcing defenses against similar threats.
0 comentários:
Postar um comentário