Apple beefs up macOS Big Sur security

Apple beefs up macOS Big Sur security
Apple beefs up macOS Big Sur security (Image credit: Shutterstock)

Security risks were discovered for macOS Big Sur back in November 2020 when developers voiced concerns over an internal file that permitted Apple apps to bypass firewall filters on demand. 

However, Apple has now released macOS Big Sur 11.2 into public beta and has removed the list of exemptions that could have led to security breaches and malware, allowing Mac users the freedom to monitor their app data again. 

MacOS Big Sur 11.2 beta 2

 A file was originally included in macOS Big Sur called “ContentFilterExclusionList,” which listed several official apps such as the App Store, the Music App, and FaceTime that would bypass any firewall installed onto the device. 

This left the affected apps and services exposed to hackers that could use the exclusion list to create malware that would bypass Mac security and ignore any third-party firewall installed on the device. This also removed the ability for users to check what Apple apps were doing with their data, or even block or monitor any operating system traffic.

These issues were initially discovered after a server outage on the macOS Big Sur launch date prevented apps from working, and developers found that Apple was forcing all official applications to have full access to the network. The connection to servers couldn't be severed to get these apps working again, even with a firewall in place.

Patrick Wardle, a security researcher who has been following the issue on his Patreon blog and Twitter account, announced that the exception list has been removed by Apple with macOS Big Sur 11.2 beta 2, which means the previously affected apps can no longer ignore firewalls and users will have the freedom to monitor their web traffic once again.

This is currently accessible for any developers or users registered in the Public Beta program, and as such isn't officially live to the general public at the time of writing. You can read more on the Apple Beta Software Program on the official website. It's easy to sign up if you wanted to be involved and present feedback on any future updates across the Apple product library. 

Via 9to5 Mac

TOPICS
Jess Weatherbed

Jess is a former TechRadar Computing writer, where she covered all aspects of Mac and PC hardware, including PC gaming and peripherals. She has been interviewed as an industry expert for the BBC, and while her educational background was in prosthetics and model-making, her true love is in tech and she has built numerous desktop computers over the last 10 years for gaming and content creation. Jess is now a journalist at The Verge.

Latest in macOS
macOS Catalina
A secret project, a stubborn developer, and a lot of glossy icons: here's the story behind macOS’s Dock as it turns 25
A woman sitting on a couch cross-legged and using a laptop
Essential apps and features to start getting the most out of your brand-new Mac
A woman sitting at a table with various objects on it, including a MacBook, a mug, a book, an opened notebook, and holding her head with her hands as if in frustration
It looks like macOS Sequoia 15.2 update breaks third-party bootable backups - and that has me worried
Genmoji Cowboy Frog Apple Intelligence
macOS Sequoia 15.3 beta brings Genmoji to Mac, allowing you to serve up custom emojis that really represent you
Person using a MacBook sat on sofa
Your Mac’s menu bar will finally get a weather widget in macOS Sequoia 15.2 – plus these Apple Intelligence features
The Apple Magic Mouse on a white surface next to the Magic Keyboard.
Planning to buy Apple’s new USB-C Magic accessories? Make sure you’re running macOS Sequoia 15.1 first
Latest in News
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Forget AI – WhatsApp is planning a simple messages feature that could be its most useful upgrade in years
NordicTrack Ultra 1
The new NordicTrack Ultra 1 treadmill looks like it was designed by an architect and costs $15,000
An Nvidia GeForce RTX 5070
Nvidia RTX 5080 stock is so barren that retailers are holding competitions where you can "win" the right to buy one for MSRP
Assassin's Creed Shadows
Ubisoft shareholder accuses publisher of 'misleading investors', plans protest outside Paris HQ
Google Gemini AI logo on a smartphone with Google background
I made an AI version of Bilbo Baggins using Goggle Gemini for free, and shared a pipe with him outside Bag End – here’s what you can now do with Gems