AI News Feed
Market watch
Cybersecurity

Apple, Microsoft and Zoom rush out patches for device-takeover flaws

Apple, Microsoft and Zoom patched takeover flaws, including an exploited Windows zero-day and screen-sharing bugs.

Apple on Thursday released emergency macOS updates for Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. According to ZDNet, the patches fix a Screen Sharing vulnerability that could let an attacker authenticate without valid credentials and then view personal files, change settings, install malware or use the Mac in a botnet. Engadget reported that attackers on the same network could exploit the flaw. Apple did not indicate the flaw had been exploited in any known attacks. Users can install the update by going to System Settings, selecting General and clicking Software Update.

Microsoft's August Patch Tuesday update, reported by ZDNet, fixes 421 vulnerabilities across Windows, Office, Exchange, Azure and SharePoint. The update targets Windows 11 25H2/24H2, Windows 11 23H2 and Windows 10. Most urgent is a Windows Ancillary Function Driver for WinSock elevation-of-privilege vulnerability that has been exploited in the wild; an attacker with low-level access can gain SYSTEM privileges without user interaction. "Exploitation has been detected in the wild, so deployment should be prioritized even though the vulnerability is rated Important rather than Critical," said patch-management provider Action1. The update also patches two other zero-days, including a Windows User Profile Service flaw that was publicly known and could give an attacker administrative privileges.

The Patch Tuesday updates are mandatory and should download and install automatically, but users are advised to double-check in Settings and reboot when prompted. Windows 10 users need to be enrolled in the free Extended Security Updates program to continue receiving security patches. Beyond the security fixes, the release includes minor changes to File Explorer, Windows Hello, Voice Access and touchpad controls. Microsoft uses an internal AI-powered scanning harness, codenamed MDASH, to find Windows vulnerabilities faster, according to ZDNet.

Separately, researchers at a cybersecurity company found a bug in Zoom's screen-sharing function that could let an attacker take over another participant's device. The flaw exists in the Zoom Workspace app for Windows, Mac, iOS, Android and Linux before the latest updates, Engadget reported. When the annotation tool is launched during a screen share, the vulnerability allows remote code execution without any action from the victim and with no visible warning. It was not clear whether the flaw had been exploited in the wild. Zoom was notified and has deployed fixes. The researchers said they used AI prompts to develop the exploit in under 24 hours. "This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort and weapons-grade budgets has collapsed," the cybersecurity company wrote in a blog post.