Any Mac App Can Purportedly Record Your Screen Without You Knowing
LIKE
TWEET
SHARE
PIN
SHARE
POST
MAIL
MORE
Posted February 11, 2018 at 4:59am by iClarified
Any Mac app can record your screen at any time without your knowledge, according to Felix Krause, founder of fastlane.
Krause says that any Mac app, sandboxed or not, has the ability to take screenshots of your screen silently without you knowing, accessing every pixel of all displays even if the app is in the background. Those images can then be fed through OCR software to read the text on the screen.
What’s the worst that could happen? ● Read password and keys from password managers ● Detect what web services you use (e.g. email provider) ● Read all emails and messages you open on your Mac ● When a developer is targeted, this allows the attacker to potentially access sensitive source code, API keys or similar data ● Learn personal information about the user, like their bank details, salary, address, etc.
To do this, a Mac developer simply needs to use CGWindowListCreateImage to generate a capture of the complete screen.
Krause has filed a radar to notify Apple about the issue. Please follow iClarified on Twitter, Facebook, or RSS for updates.
To prevent these routines is now APPLE's turn ...
... or does anyone have the desire / an idea to write a small app to uncover the described functions and then delete the septic program?!?
Not being funny or taking Apple’s side but if there was a app detailing all the vulnerabilities found in Windows OS daily it will be a lot more than Mac OS The only difference is a vulnerability found in Mac OS is made breaking news
And windows doesn’t? LOL. I’m a developer and it’s pretty much a standard access of any app. Also passwords doesn’t show password unless you click on the show password and besides, it all comes down to “install only the apps you trust.” LOL