Microsoft Excel users need to patch now - but Mac owners are out of luck

Microsoft Excel
(Image credit: Shutterstock / 200dgr)

A zero-day vulnerability in spreadsheet software Microsoft Excel is reportedly being abused by cybercriminals in real-world scenarios.

According to an advisory issued by Microsoft, the security feature bypass bug could allow unauthenticated threat actors to launch attacks against vulnerable users with relative ease.

To exploit the flaw, an attacker would need to trick a victim into opening a malicious Excel document, perhaps delivered via phishing email or malicious website.

The vulnerability has been handed a score of 7.8/10 per the Common Vulnerability Scoring System (CVSS), placing it in the high severity category.

What about Excel on Mac?

Although Microsoft has now delivered a patch for Excel on Windows devices as part of this month’s Patch Tuesday, Apple customers remain vulnerable to the exploit.

The company explained that Microsoft 365 users on Mac devices will have to wait a little longer for a patch, but did not specify a reason or time-frame. 

“The security update for Microsoft Office 2019 for Mac and Microsoft OFfice LTSC for Mac 2021 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information,” the advisory explained.

To shield against attack, Windows users are advised to update their Excel installations to the latest build immediately. Mac users, meanwhile, should avoid interacting with unsolicited email attachments and avoid downloading content from unfamiliar sources while they await a full patch.

More generally, meanwhile, users should ensure their devices are protected by a leading antivirus service and that all software patches are installed on a regular basis.

Via Bleeping Computer

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection