Another Apple QuickTime bug reported

By

US-CERT has issued an alert concerning a new zero-day vulnerability in the Apple QuickTime media player.


Attackers can exploit the flaw to install malicious code on a user's machine if they open a specially crafted QuickTime file, US-CERT said Wednesday evening.

The researcher who reportedly discovered the vulneraiblity, Petko Petkov of the Gnucitizen think tank, could not immediately be reached for comment.

"US-CERT encourages users to use caution when opening QuickTime files, and apply best security practices...to help mitigate the risks," according to the alert.

So far this year, Apple has delivered three security updates to remedy bugs in QuickTime.

Vulnerable client-side software is nothing new, as researchers have reported similar problems in other offerings.

An Apple spokeswoman did not respond to a request for comment on Thursday.

See original article on scmagazineus.com
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Log In

  |  Forgot your password?