news.volyx.in

Security Flaws in Adobe Acrobat Reader Allow Gaining Root on macOS Silently (rekken.github.io)

871 points by feross · 2336 days ago · 418 comments on HN

Article summary

Security researcher Yuebin Sun discovered three critical vulnerabilities in Adobe Acrobat Reader DC for macOS, which can be exploited to gain root access on the system without user awareness. The vulnerabilities are related to the software's update mechanism and can be triggered by a normal user with SIP enabled. Adobe has patched the vulnerabilities, but the patch only addresses the specific issues and does not add sandboxing to the root helper tool. The vulnerabilities highlight the importance of securing software update mechanisms and the potential risks of using complex and fragile autoupdate permission bypasses.

Main themes

  • Adobe Acrobat Reader vulnerabilities
  • macOS security
  • software update mechanisms
  • PDF viewers and alternatives
  • user security and risk
  • software complexity and legacy code
  • autoupdate permission bypasses

What commenters say

  • Some users question the need for a PDF reader to have a non-sandboxed daemon to escalate privileges, citing security concerns.
  • Others argue that Adobe's software is often required for specific tasks, such as filling out forms, and that alternatives may not be sufficient.
  • There is a disagreement about the effectiveness of Preview, the default PDF viewer on macOS, with some users finding it lacking for certain tasks.
  • Some commenters express frustration with the security record of Adobe software and the potential risks of using it.
  • A few users mention that they use alternative PDF viewers or take extra precautions, such as using a virtual machine, when dealing with sensitive documents.
  • Some argue that the issues with Adobe Acrobat Reader are due to lazy programming or a lack of concern for user security.
  • Others suggest that the problems may be related to the complexity and legacy of the software.