First published: Wed Jun 13 2018(Updated: )
An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Santa | <=0.9.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.