macOS 'Quick Look' exploit could reveal all your encrypted data

macOS Quick Look hacking

Quick Look is one of macOS’s most convenient features, but one developer has proven it’s also extremely vulnerable to hacking.

Apple's Quick Look mechanism generates and caches thumbnails of files, images, folders and other data to give users fast and easy access. That’s generally what Quick Look does with all your files, but a security researcher named Wojciech Regula realized the feature is doing the same thing with all your encrypted data and saves those said thumbnails to an unencrypted location.

This vulnerability would allow a hacker to easily capture snippets of original files, including those contained in encrypted containers, simply by rooting out Quick Look’s cache of thumbnails.

Mo’ speed, mo’ problems

Regula simulated such a hack by uploading two images into two separate encrypted containers, one encoded in VeraCrypt and another with macOS Encrypted HFS+/APFS. Using simple commands, the researcher both images through their file paths, allowing him to access a miniature version of the original files.

As if seeing thumbnails images of your private images wasn’t bad enough, Regula also showed how the Quick Look’s backend can also reveal sensitive documents. Unfortunately, Quick Look also does a great job of caching any additional drives you might have plugged into your Mac, so files stored on thumb drives or external hard drives.

So what can you do? Fortunately, users can secure their encrypted files by manually clearing the Quick Look and unmount their encrypted container and Regula notes that Apple has even made a utility called ‘qlmanage’ just for this task.

It seems like the best way to keep your data secure from Quick Look is to completely divorce it from your Mac – which isn’t convenient at all. So hopefully Apple releases a fix for this vulnerability in a near future macOS update.

Via AppleInsider

TOPICS
Kevin Lee

Kevin Lee was a former computing reporter at TechRadar. Kevin is now the SEO Updates Editor at IGN based in New York. He handles all of the best of tech buying guides while also dipping his hand in the entertainment and games evergreen content. Kevin has over eight years of experience in the tech and games publications with previous bylines at Polygon, PC World, and more. Outside of work, Kevin is major movie buff of cult and bad films. He also regularly plays flight & space sim and racing games. IRL he's a fan of archery, axe throwing, and board games.

Latest in macOS
macOS Catalina
A secret project, a stubborn developer, and a lot of glossy icons: here's the story behind macOS’s Dock as it turns 25
A woman sitting on a couch cross-legged and using a laptop
Essential apps and features to start getting the most out of your brand-new Mac
A woman sitting at a table with various objects on it, including a MacBook, a mug, a book, an opened notebook, and holding her head with her hands as if in frustration
It looks like macOS Sequoia 15.2 update breaks third-party bootable backups - and that has me worried
Genmoji Cowboy Frog Apple Intelligence
macOS Sequoia 15.3 beta brings Genmoji to Mac, allowing you to serve up custom emojis that really represent you
Person using a MacBook sat on sofa
Your Mac’s menu bar will finally get a weather widget in macOS Sequoia 15.2 – plus these Apple Intelligence features
The Apple Magic Mouse on a white surface next to the Magic Keyboard.
Planning to buy Apple’s new USB-C Magic accessories? Make sure you’re running macOS Sequoia 15.1 first
Latest in News
European Union technical background
EU tech companies push for digital sovereignty, reducing reliance on US and others
Star Wars Knights of the Old Republic
Knights of the Old Republic remake developer Saber Interactive states all its projects are 'still in development'
google nest
Google is slowly phasing out its Assistant helper to make room for Gemini's reign in smartphones - here’s how it’s doing the same for smart home devices
Renault 5 Turbo 3E
Renault unveils its wildest EV to date and it comes with in-wheel motors and a rally-style vertical handbrake for drifting
Circular smart ring
Circular's new smart ring is getting blood pressure and blood glucose monitoring before the Apple Watch
Gemini on a mobile phone.
Worryingly, Google Gemini’s new AI image generation features can be used to remove watermarks from images and I'm concerned