A security researcher has identified a method for untrusted websites to freeze macOS systems, dubbed "The Deathray." The technique exploits browser behavior to render machines unresponsive.
Security researcher Auberon detailed the vulnerability on their blog, explaining how malicious websites can trigger a freeze state on Mac computers. The attack leverages browser resource consumption patterns to overwhelm system processes.
The findings have generated significant discussion in the developer community, with 75 comments on Hacker News and 120 upvotes, indicating widespread interest among security professionals.
The vulnerability affects standard web browsing behavior, meaning users visiting a compromised or malicious site could experience system freezes without additional prerequisites. This differs from traditional exploits requiring user interaction beyond normal browsing.
The discovery highlights ongoing security challenges in web browser design and macOS system resource management. Browser vendors and Apple may need to implement additional safeguards to prevent resource exhaustion attacks.
The full technical details are available at auberon.xyz, where the researcher provides an in-depth analysis of the vulnerability mechanism and potential mitigation strategies.
Hardware wallet maker Trezor confirmed a data breach affecting its email provider, exposing hundreds of thousands of crypto owners to targeted scams. This marks the second breach involving a third-party service that Trezor depends on.
A US judge dismissed two lawsuits against LinkedIn for scanning users' browser extensions, ruling that downloading extensions constitutes voluntary data exposure. The Microsoft subsidiary prevailed on its motion to dismiss.
Florida's Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database after attackers exploited stolen credentials from a police department employee.
Threat actors are chaining critical vulnerabilities in JFrog Artifactory to bypass authentication and deploy Rust-based backdoors on self-hosted servers. The attacks grant attackers administrative privileges on vulnerable instances.