<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #macOS</title><description>Cybersecurity articles tagged #macOS on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Apple Patches iOS/iPadOS 18 and macOS: 108 Vulnerabilities Addressed</title><link>https://runtimerebel.com/blog/apple-patches-ios-ipados-18-and-macos-108-vulnerabilities-addressed</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-patches-ios-ipados-18-and-macos-108-vulnerabilities-addressed</guid><description>Apple has released significant security updates for iOS/iPadOS 18 and macOS, fixing 108 vulnerabilities, none exploited in the wild.</description><pubDate>Tue, 18 Aug 2026 00:42:55 GMT</pubDate><category>Apple</category><category>iOS</category><category>iPadOS</category><category>macOS</category><category>WebKit</category></item><item><title>Apple Screen Sharing Exploits: Secure Your macOS Systems Now</title><link>https://runtimerebel.com/blog/apple-screen-sharing-exploits-secure-your-macos-systems-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-screen-sharing-exploits-secure-your-macos-systems-now</guid><description>Critical vulnerabilities in Apple Screen Sharing are actively exploited, allowing system compromise. Learn how to secure macOS against these threats.</description><pubDate>Mon, 17 Aug 2026 16:20:27 GMT</pubDate><category>Apple</category><category>macOS</category><category>Exploitation</category><category>Remote Access</category><category>Screen Sharing</category></item><item><title>AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control</title><link>https://runtimerebel.com/blog/amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control</guid><description>AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.</description><pubDate>Sun, 16 Aug 2026 16:14:35 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickFix</category><category>Chromium</category><category>AmnesiaStealer</category></item><item><title>macOS Screen Sharing Flaw Exploited to Deploy Monero Miner</title><link>https://runtimerebel.com/blog/macos-screen-sharing-flaw-exploited-to-deploy-monero-miner</link><guid isPermaLink="true">https://runtimerebel.com/blog/macos-screen-sharing-flaw-exploited-to-deploy-monero-miner</guid><description>The Netherlands NCSC warns that hackers are actively exploiting an authentication bypass flaw in macOS Screen Sharing to deploy cryptocurrency miners.</description><pubDate>Fri, 14 Aug 2026 16:41:52 GMT</pubDate><category>CVE-2026-65400</category><category>macOS</category><category>Cryptojacking</category><category>Monero</category><category>Authentication Bypass</category></item><item><title>ClickFix Attacks Deliver macOS Stealer Targeting Crypto</title><link>https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</guid><description>ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.</description><pubDate>Mon, 10 Aug 2026 00:59:16 GMT</pubDate><category>macOS</category><category>Malware</category><category>Cryptocurrency</category><category>Phishing</category><category>Credential Theft</category></item><item><title>NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS</title><link>https://runtimerebel.com/blog/natjack-attacks-exploiting-nat-trust-in-windows-linux-macos</link><guid isPermaLink="true">https://runtimerebel.com/blog/natjack-attacks-exploiting-nat-trust-in-windows-linux-macos</guid><description>Synack&apos;s research reveals NatJack attacks, a new class of NAT exploitation affecting Windows, Linux, and macOS, leveraging trust assumptions.</description><pubDate>Sun, 09 Aug 2026 00:58:42 GMT</pubDate><category>Windows</category><category>Linux</category><category>macOS</category><category>NatJack</category><category>NAT</category></item><item><title>XCSSET v40 Malware Targets macOS Developers via Xcode</title><link>https://runtimerebel.com/blog/xcsset-v40-malware-targets-macos-developers-via-xcode</link><guid isPermaLink="true">https://runtimerebel.com/blog/xcsset-v40-malware-targets-macos-developers-via-xcode</guid><description>Discover how XCSSET v40 targets macOS developers using fileless persistence, memory execution, and Xcode project supply chain attacks.</description><pubDate>Sat, 08 Aug 2026 01:00:18 GMT</pubDate><category>XCSSET</category><category>macOS</category><category>Xcode</category><category>Supply Chain Attack</category><category>Malware</category></item><item><title>ClickFix Attack Deploys macOS Infostealer for Crypto Theft</title><link>https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</guid><description>The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.</description><pubDate>Fri, 07 Aug 2026 02:08:44 GMT</pubDate><category>ClickFix</category><category>macOS</category><category>Infostealer</category><category>Cryptocurrency</category><category>Golang</category></item><item><title>ClickFix Campaign Uses Server-Side Fingerprinting to Hide macOS Malware</title><link>https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</guid><description>Over 250 ClickFix domains utilize server-side browser fingerprinting to evade security sandboxes and distribute macOS infostealers like AMOS.</description><pubDate>Thu, 06 Aug 2026 01:56:14 GMT</pubDate><category>Phishing</category><category>Malware</category><category>Credential Theft</category><category>macOS</category><category>Atomic Stealer</category></item><item><title>DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft</title><link>https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</guid><description>North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.</description><pubDate>Thu, 30 Jul 2026 21:11:51 GMT</pubDate><category>macOS</category><category>Lazarus Group</category><category>Malvertising</category><category>Cryptocurrency</category><category>DPRK</category></item><item><title>Apple July 2026 Security Updates: Patching macOS 26 and Safari</title><link>https://runtimerebel.com/blog/apple-july-2026-security-updates-patching-macos-26-and-safari</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-july-2026-security-updates-patching-macos-26-and-safari</guid><description>Apple releases widespread security updates for macOS 26, legacy macOS 14 and 15, iOS, and Safari. Organizations must patch to mitigate remote execution risks.</description><pubDate>Wed, 29 Jul 2026 10:43:22 GMT</pubDate><category>Apple</category><category>macOS</category><category>Safari</category><category>iOS</category><category>Security Updates</category><category>Patch Management</category></item><item><title>Claude Cowork Sandbox Escape: VM to macOS File Access</title><link>https://runtimerebel.com/blog/claude-cowork-sandbox-escape-vm-to-macos-file-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-cowork-sandbox-escape-vm-to-macos-file-access</guid><description>A critical sandbox escape vulnerability in Anthropic&apos;s Claude Cowork allows AI agents to break out of their Linux VM, gaining full file access on macOS hosts, affecting…</description><pubDate>Thu, 23 Jul 2026 17:26:58 GMT</pubDate><category>Claude Cowork</category><category>Anthropic</category><category>macOS</category><category>Sandbox Escape</category><category>VM Escape</category><category>AI Security</category><category>Data Privacy</category></item><item><title>ClickLock macOS Malware: Password Theft via Forced Login Prompt</title><link>https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</guid><description>ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password.</description><pubDate>Fri, 17 Jul 2026 02:45:47 GMT</pubDate><category>macOS</category><category>ClickLock</category><category>Information Stealer</category><category>Password Theft</category><category>Social Engineering</category></item><item><title>ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops</title><link>https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</guid><description>ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.</description><pubDate>Thu, 16 Jul 2026 14:03:10 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickLock</category><category>Social Engineering</category><category>Persistence</category></item><item><title>PamStealer: New macOS Malware Targets PAM for Password Exfiltration</title><link>https://runtimerebel.com/blog/pamstealer-new-macos-malware-targets-pam-for-password-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/pamstealer-new-macos-malware-targets-pam-for-password-exfiltration</guid><description>Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.</description><pubDate>Fri, 03 Jul 2026 10:38:45 GMT</pubDate><category>PamStealer</category><category>macOS</category><category>Jamf Threat Labs</category><category>AppleScript</category><category>Credential Theft</category></item><item><title>June Apple Security Updates for iOS, macOS, Safari: Patch Now</title><link>https://runtimerebel.com/blog/june-apple-security-updates-for-ios-macos-safari-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/june-apple-security-updates-for-ios-macos-safari-patch-now</guid><description>Apple released essential security updates for iOS/iPadOS, macOS, and Safari in June. Learn why timely patching is critical for protecting your devices and data.</description><pubDate>Tue, 30 Jun 2026 12:52:07 GMT</pubDate><category>Apple</category><category>iOS</category><category>iPadOS</category><category>macOS</category><category>Safari</category><category>Security Updates</category><category>Patch Management</category></item><item><title>AirDrop and Quick Share: Proximity Flaws Cause Crashes and Bypass Checks</title><link>https://runtimerebel.com/blog/airdrop-and-quick-share-proximity-flaws-cause-crashes-and-bypass-checks</link><guid isPermaLink="true">https://runtimerebel.com/blog/airdrop-and-quick-share-proximity-flaws-cause-crashes-and-bypass-checks</guid><description>Researchers found six security flaws in AirDrop and Quick Share, enabling nearby attackers to crash devices and bypass security checks without user interaction.</description><pubDate>Tue, 30 Jun 2026 12:49:12 GMT</pubDate><category>AirDrop</category><category>Quick Share</category><category>macOS</category><category>iOS</category><category>Android</category><category>Wireless Security</category><category>Proximity Attack</category><category>Denial of Service</category><category>Privacy Bypass</category></item><item><title>JINX-0164 Targets Crypto Firms with macOS Malware and Fake Lures</title><link>https://runtimerebel.com/blog/jinx-0164-targets-crypto-firms-with-macos-malware-and-fake-lures</link><guid isPermaLink="true">https://runtimerebel.com/blog/jinx-0164-targets-crypto-firms-with-macos-malware-and-fake-lures</guid><description>The JINX-0164 threat actor targets cryptocurrency firms via recruitment-themed social engineering, macOS-specific malware, and CI/CD infrastructure exploits.</description><pubDate>Thu, 28 May 2026 09:22:52 GMT</pubDate><category>JINX 0164</category><category>macOS</category><category>Cryptocurrency</category><category>CI CD</category><category>Social Engineering</category></item><item><title>AI-Assisted macOS Kernel Exploit on Apple M5 Hardware</title><link>https://runtimerebel.com/blog/ai-assisted-macos-kernel-exploit-on-apple-m5-hardware</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-macos-kernel-exploit-on-apple-m5-hardware</guid><description>Security researchers used Anthropic’s Mythos AI to develop a macOS kernel memory corruption exploit for the Apple M5 chip in just five days. Patch now.</description><pubDate>Thu, 21 May 2026 20:42:22 GMT</pubDate><category>Apple M5</category><category>macOS</category><category>Anthropic Mythos</category><category>Kernel Exploit</category><category>Memory Corruption</category><category>Zero-Day</category></item><item><title>SHub Reaper Stealer Backdoors macOS via Spoofed Apps</title><link>https://runtimerebel.com/blog/shub-reaper-stealer-backdoors-macos-via-spoofed-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/shub-reaper-stealer-backdoors-macos-via-spoofed-apps</guid><description>SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.</description><pubDate>Tue, 19 May 2026 20:42:42 GMT</pubDate><category>SHub Reaper</category><category>macOS</category><category>Stealer</category><category>Backdoor</category><category>Phishing</category><category>AppleScript</category></item><item><title>SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor</title><link>https://runtimerebel.com/blog/shub-macos-infostealer-spoofs-apple-security-updates-installs-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/shub-macos-infostealer-spoofs-apple-security-updates-installs-backdoor</guid><description>A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.</description><pubDate>Tue, 19 May 2026 00:57:05 GMT</pubDate><category>SHub</category><category>macOS</category><category>Infostealer</category><category>AppleScript</category><category>Backdoor</category><category>Phishing</category></item><item><title>CVE-2024-38812: How to Mitigate VMware Fusion Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2024-38812-how-to-mitigate-vmware-fusion-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-38812-how-to-mitigate-vmware-fusion-privilege-escalation</guid><description>VMware Fusion 13.6 fixes a high-severity local privilege escalation flaw (CVE-2024-38812) that allows attackers to gain root access on macOS hosts.</description><pubDate>Thu, 14 May 2026 09:04:56 GMT</pubDate><category>CVE-2024-38812</category><category>VMware Fusion</category><category>Broadcom</category><category>macOS</category><category>Privilege Escalation</category></item><item><title>Apple macOS Sonoma 14.5 and iOS 17.5 Patch Technical Analysis</title><link>https://runtimerebel.com/blog/apple-macos-sonoma-14-5-and-ios-17-5-patch-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-macos-sonoma-14-5-and-ios-17-5-patch-technical-analysis</guid><description>Apple addresses critical security flaws in macOS and iOS, including kernel-level RCE and a privacy bug causing deleted media to reappear on devices.</description><pubDate>Tue, 12 May 2026 12:49:41 GMT</pubDate><category>Apple</category><category>macOS</category><category>iOS</category><category>CVE-2024-27822</category><category>Kernel Security</category></item><item><title>Apple May 2024 Security Updates Address 84 Vulnerabilities</title><link>https://runtimerebel.com/blog/apple-may-2024-security-updates-address-84-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-may-2024-security-updates-address-84-vulnerabilities</guid><description>Apple&apos;s May 2024 security updates patch 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and visionOS. Immediate patching is crucial for all users.</description><pubDate>Tue, 12 May 2026 00:50:06 GMT</pubDate><category>Apple</category><category>iOS</category><category>macOS</category><category>iPadOS</category><category>watchOS</category><category>tvOS</category><category>visionOS</category><category>Security Update</category><category>Vulnerabilities</category></item><item><title>MacSync Stealer Distributed via Malicious Homebrew Ad Campaign</title><link>https://runtimerebel.com/blog/macsync-stealer-distributed-via-malicious-homebrew-ad-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/macsync-stealer-distributed-via-malicious-homebrew-ad-campaign</guid><description>Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.</description><pubDate>Fri, 01 May 2026 20:25:24 GMT</pubDate><category>MacSync Stealer</category><category>Homebrew</category><category>macOS</category><category>Malvertising</category><category>Data Theft</category></item><item><title>Sapphire Sleet&apos;s ClickFix: North Korea Targets macOS Users</title><link>https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</guid><description>North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.</description><pubDate>Thu, 16 Apr 2026 20:22:49 GMT</pubDate><category>Sapphire Sleet</category><category>ClickFix</category><category>macOS</category><category>North Korea</category><category>Phishing</category><category>Data Theft</category><category>APT</category></item><item><title>OpenAI Revokes macOS App Certificate Following Supply Chain Attack</title><link>https://runtimerebel.com/blog/openai-revokes-macos-app-certificate-following-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-revokes-macos-app-certificate-following-supply-chain-attack</guid><description>OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.</description><pubDate>Mon, 13 Apr 2026 08:48:46 GMT</pubDate><category>OpenAI</category><category>macOS</category><category>Axios</category><category>GitHub Actions</category><category>Supply Chain Security</category></item><item><title>Exchange Online Mailbox Access Issues Persist for Outlook Users</title><link>https://runtimerebel.com/blog/exchange-online-mailbox-access-issues-persist-for-outlook-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/exchange-online-mailbox-access-issues-persist-for-outlook-users</guid><description>Microsoft Exchange Online users on Outlook mobile and macOS are experiencing intermittent mailbox access issues for weeks; investigation ongoing.</description><pubDate>Fri, 03 Apr 2026 12:21:54 GMT</pubDate><category>Microsoft Exchange Online</category><category>Outlook Mobile</category><category>macOS</category><category>Service Degradation</category><category>Availability Issues</category></item><item><title>Apple DarkSword Protection Expands: Mitigating CVE-2023-38604 Zero-Click Exploits</title><link>https://runtimerebel.com/blog/apple-darksword-protection-expands-mitigating-cve-2023-38604-zero-click-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-darksword-protection-expands-mitigating-cve-2023-38604-zero-click-exploits</guid><description>Apple expands DarkSword exploit protection to all users, enhancing defenses against state-sponsored and commercial zero-click attacks like CVE-2023-38604.</description><pubDate>Thu, 02 Apr 2026 16:27:21 GMT</pubDate><category>Apple</category><category>DarkSword</category><category>CVE-2023-38604</category><category>Zero Click</category><category>Exploit Kit</category><category>State Sponsored</category><category>Commercial Spyware</category><category>iOS</category><category>macOS</category><category>iPadOS</category><category>watchOS</category><category>tvOS</category></item><item><title>Axios npm Package Hijacked: Cross-Platform Malware Distribution</title><link>https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</guid><description>Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.</description><pubDate>Tue, 31 Mar 2026 16:29:10 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Remote Access Trojan</category><category>Malware</category><category>JavaScript</category><category>Linux</category><category>Windows</category><category>macOS</category></item><item><title>macOS Terminal ClickFix Protections: Blocking Malicious Shell Commands</title><link>https://runtimerebel.com/blog/macos-terminal-clickfix-protections-blocking-malicious-shell-commands</link><guid isPermaLink="true">https://runtimerebel.com/blog/macos-terminal-clickfix-protections-blocking-malicious-shell-commands</guid><description>Apple introduces Terminal warnings in macOS Sequoia 15.2 to combat ClickFix social engineering attacks that trick users into executing malicious shell scripts.</description><pubDate>Mon, 30 Mar 2026 16:28:10 GMT</pubDate><category>macOS</category><category>Sequoia</category><category>ClickFix</category><category>Social Engineering</category><category>Terminal</category><category>Malware</category></item><item><title>Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads</title><link>https://runtimerebel.com/blog/infinity-stealer-macos-malware-analyzing-clickfix-lures-and-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/infinity-stealer-macos-malware-analyzing-clickfix-lures-and-payloads</guid><description>Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.</description><pubDate>Sat, 28 Mar 2026 16:13:39 GMT</pubDate><category>macOS</category><category>Infinity Stealer</category><category>Infostealer</category><category>Nuitka</category><category>ClickFix</category><category>Social Engineering</category></item><item><title>ClickFix Social Engineering Drops Infiniti Stealer on macOS</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-drops-infiniti-stealer-on-macos</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-drops-infiniti-stealer-on-macos</guid><description>Attackers use fake Cloudflare CAPTCHA pages and ClickFix tactics to deliver the Python-based Infiniti Stealer to macOS systems via terminal commands.</description><pubDate>Sat, 28 Mar 2026 12:21:09 GMT</pubDate><category>macOS</category><category>Infiniti Stealer</category><category>ClickFix</category><category>Social Engineering</category><category>Cloudflare Lures</category></item><item><title>Apple Addresses 85 Vulnerabilities in Recent OS Updates</title><link>https://runtimerebel.com/blog/apple-addresses-85-vulnerabilities-in-recent-os-updates</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-addresses-85-vulnerabilities-in-recent-os-updates</guid><description>Apple released significant security updates patching 85 vulnerabilities across macOS, iOS, iPadOS, tvOS, watchOS, and visionOS, with no active exploitation reported.</description><pubDate>Thu, 26 Mar 2026 00:41:00 GMT</pubDate><category>Apple</category><category>macOS</category><category>iOS</category><category>iPadOS</category><category>tvOS</category><category>watchOS</category><category>visionOS</category><category>Security Update</category><category>Vulnerabilities</category><category>Patch Management</category></item><item><title>CVE-2026-20643: Apple Patches WebKit Same-Origin Policy Bypass</title><link>https://runtimerebel.com/blog/cve-2026-20643-apple-patches-webkit-same-origin-policy-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20643-apple-patches-webkit-same-origin-policy-bypass</guid><description>Apple addresses CVE-2026-20643, a critical WebKit Navigation API flaw allowing Same-Origin Policy bypass on iOS and macOS. Deploy updates immediately.</description><pubDate>Wed, 18 Mar 2026 08:20:23 GMT</pubDate><category>Apple</category><category>WebKit</category><category>CVE-2026-20643</category><category>iOS</category><category>macOS</category><category>SOP Bypass</category></item><item><title>Apple CVE-2026-20643: WebKit Flaw Fixed via Background Update</title><link>https://runtimerebel.com/blog/apple-cve-2026-20643-webkit-flaw-fixed-via-background-update</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-cve-2026-20643-webkit-flaw-fixed-via-background-update</guid><description>Apple deploys the first Background Security Improvements update to address a critical WebKit vulnerability (CVE-2026-20643) across iOS and macOS platforms.</description><pubDate>Wed, 18 Mar 2026 04:44:24 GMT</pubDate><category>Apple</category><category>WebKit</category><category>CVE-2026-20643</category><category>iOS</category><category>macOS</category><category>Patch Management</category></item><item><title>ClickFix Campaigns Deliver MacSync macOS Infostealer via Fake AI Tools</title><link>https://runtimerebel.com/blog/clickfix-campaigns-deliver-macsync-macos-infostealer-via-fake-ai-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaigns-deliver-macsync-macos-infostealer-via-fake-ai-tools</guid><description>Threat actors use ClickFix social engineering tactics to deploy the MacSync infostealer on macOS systems via fraudulent AI software installers.</description><pubDate>Mon, 16 Mar 2026 12:24:32 GMT</pubDate><category>Macsync</category><category>ClickFix</category><category>macOS</category><category>Infostealer</category><category>Social Engineering</category></item><item><title>Apple Patches CVE-2023-43010 WebKit Vulnerability in Older Devices</title><link>https://runtimerebel.com/blog/apple-patches-cve-2023-43010-webkit-vulnerability-in-older-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-patches-cve-2023-43010-webkit-vulnerability-in-older-devices</guid><description>Apple backports fixes for CVE-2023-43010 in older iOS and macOS versions to defend against the Coruna exploit kit targeting WebKit memory corruption.</description><pubDate>Thu, 12 Mar 2026 12:17:21 GMT</pubDate><category>CVE-2023-43010</category><category>Apple</category><category>iOS</category><category>macOS</category><category>WebKit</category><category>Coruna Exploit Kit</category></item><item><title>npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert</title><link>https://runtimerebel.com/blog/npm-malware-openclaw-ai-openclawai-macos-credential-theft-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-malware-openclaw-ai-openclawai-macos-credential-theft-alert</guid><description>Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.</description><pubDate>Mon, 09 Mar 2026 20:11:58 GMT</pubDate><category>NPM</category><category>macOS</category><category>Malware</category><category>RAT</category><category>OpenClaw</category><category>Supply Chain Attack</category></item><item><title>macOS coreaudiod Type Confusion Exploitation: CVE-2024-54529</title><link>https://runtimerebel.com/blog/macos-coreaudiod-type-confusion-exploitation-cve-2024-54529</link><guid isPermaLink="true">https://runtimerebel.com/blog/macos-coreaudiod-type-confusion-exploitation-cve-2024-54529</guid><description>Analysis of CVE-2024-54529, a critical type confusion vulnerability in macOS coreaudiod, detailing its exploitation and necessary mitigations.</description><pubDate>Wed, 25 Feb 2026 04:47:23 GMT</pubDate><category>macOS</category><category>Coreaudiod</category><category>CVE-2024-54529</category><category>Type Confusion</category><category>Exploitation</category><category>CoreAudio</category><category>CVE-2025-31235</category></item></channel></rss>