Skip to main content

Core Security Publishes iCal Vulnerabilitie

Core Security Publishes iCal Vulnerabilitie

It was back in January that Core Security discovered the vulnerabilities in iCal, the calendar application that’s part of the Mac OS X. Two of them could cause the computer to crash, while the third could possibly allow a hacker to take control of the computer.

Ivan Acre, CTO of Core Security Technologies, explained to MacNewsWorld that “the third one can be used to compromise the computer with all the rights of the user running the application. For that to happen, the most likely scenario is the user opening up an e-mail or a calendar file that is malicious and has been specially crafted. If the user then edits the file, the Mac would be compromised. It requires some form of assistance."

Recommended Videos

Understandably, they informed Apple of the problem, and Apple promised a fix for the problem by May 19. When that didn’t happen, Core decided to publish the vulnerabilities, as well as a timeline of its correspondence on the topic with Apple.

"We thought, since day one, that we needed to balance the need for generating a fix with the need for warning users to be aware of the problem and their exposure and being able to do something about it," Acre said. He said that Mac OS X 10.5.1 and 10.5.2 are both affected, and iCal versions 3.0.1 and 3.0.2.

Digital Trends Staff
Digital Trends has a simple mission: to help readers easily understand how tech affects the way they live. We are your…
Is Apple’s upcoming M4 Mac event still happening? I’m skeptical
Russian YouTuber Romancev768 with what is claimed to be a real M4 MacBook Pro unit.

Over the last few weeks, the endless stream of M4 MacBook Pro leaks has been almost inescapable. We’ve seen photos, unboxing videos, even M4 laptops reportedly going up for sale way ahead of time. Ye.t despite all that, there’s been one thing that has stopped me from fully believing that these leaks are legitimate -- despite a well-known reporter claiming that they’re authentic.

That’s because in all the leaks we’ve seen, the box of the M4 MacBook Pro has come with the same black-and-gray wallpaper that Apple used for its M3 line of MacBook Pros. It’s something that has bugged me ever since I first noticed it. But what if the use of an old wallpaper isn't proof that these leaks are fakes, but is actually a clue about what Apple is about to do next?
The wallpaper of it all

Read more
These M4 MacBook Pro leaks are getting insane, and I don’t know what to believe anymore
An open MacBook Pro on a table.

Apple has yet to announce an October Mac event, but leaks for the M4 MacBook Pro continue to circulate. A new tweet from Apple leaker ShrimpApplePro and a new Russian unboxing video have been spotted by Tom's Hardware, giving this possibly true and definitely unprecedented Apple leak more steam. The tweet claims a seller on a private Facebook group has 200 units of the M4 MacBook Pro for sale, adding: "This is probably the biggest warehouse leakage I've ever seen."

https://x.com/VNchocoTaco/status/1843133165302591861?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1843133165302591861%7Ctwgr%5E3d007d4bc86ddf38301ce5446103d04c8e8215f5%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fwww.tomshardware.com%2Flaptops%2Fapple-macbook-pro-m4-leakage-gets-serious-with-200-units-reportedly-up-for-sale-on-social-media

Read more
I’m worried Apple will skip its October event – here’s what that means for the M4 MacBook Pro
Apple CEO Tim Cook looks at a display of brand new redesigned MacBook Air laptop during the WWDC22

For months now, we’ve been hearing that Apple is set to announce a boatload of new products -- including the M4 MacBook Pro range, fresh iPads, and more -- at an event this October. Yet a new report suggests that things might not be quite so simple after all.

In his latest Power On newsletter, Bloomberg journalist Mark Gurman says that Apple is set to reveal these new products “around the end of October,” with the devices going on sale on Friday, November 1. So far, so expected.

Read more