Podcast Detail

SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10094.mp3

Podcast Logo
Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Tuesday, September 15th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in Cloud
 Security. Well, today was one of the few days where we knew
 there was a big Apple update going to come. It was Apple's
 sort of annual big update where they released the next
 major version of their operating systems. This time
 we are up for iOS and macOS 27. With that, of course, we
 also got, aside from a lot of features, we got fixes for
 vulnerabilities. 261 vulnerabilities. Now, overall,
 this isn't sort of terribly out of range for Apple. It is
 a record, but we had like, you know, around 200 before. Well,
 on average, I would say more like around 100. So definitely
 more than normal, even though not an explosion like we have
 seen like with Microsoft and Oracle. As far as the
 vulnerabilities go, nothing that sort of terribly sticks
 out here. Nothing that was already exploited before
 today. Now, for everybody who isn't willing to make the leap
 to the 27 version of the operating system, there is
 also a 26.7 version that is just a bug fix, security fix
 release, and does not include any new features. So
 definitely consider that if you want to hold off a little
 bit. And that's usually recommended with any major
 update like this. As far as sort of known issues go, well,
 if you use Little Snitch, the third-party firewall for
 macOS, they released an update a couple weeks ago that
 specifically stated you should apply it before upgrading to
 27. Objective-C, they have a couple of additional utilities
 like BlockBlock, for example, is one that came out with a
 new release that improved macOS 27 compatibility. So
 definitely something that you also want to apply. I applied
 it after upgrading and haven't seen any bad effects there
 yet. Other issues, haven't really seen any sort of
 specific issues. There may be a problem with some of the
 Microsoft single sign-on handovers. I've run into it
 with one particular site where Safari is having issues. Other
 browsers after upgrading have not had any issues. Of course,
 Safari also was updated as part of this release. So
 again, this affects all the operating systems from Apple
 iOS, macOS, iPadOS, VisionOS, watchOS, all of them, and tvOS
 all got updates. So apply them. But like I said, you can
 still sort of go with the 26.7 version if you want to stay a
 little bit on the safe end. And with the new version of
 macOS, we also got a new version of Homebrew. Homebrew
 is a system, so much like apt, yum, and some of these package
 managers that you're familiar with in the Linux world to
 install various open source packages. And as any of these
 ecosystems, of course, they're battling with supply chain
 issues. Well, this new version, version 7, has some
 specific fixes kind of that make it easier, for example,
 to scan for dependencies and also a new feed being offered
 by Homebrew that can be used to essentially identify
 malicious or backdoored or compromised, I should probably
 say, dependencies. So definitely a step forward.
 There's also now a GUI for those of you who like it,
 haven't looked at the GUI myself yet. There are a couple
 similar projects, of course, out there. I think Homebrew is
 probably the biggest one. What I sort of always liked about
 Homebrew is that it usually does not require you to run
 commands as root, just in very few exceptions where root
 access is required. Another related issue is now sometimes
 when you're downloading a package from Homebrew, it
 needs to be compiled. So you need to have a compiler,
 typically Xcode. I have not seen sort of a simple update
 yet for Xcode 27. The latest in the App Store is still 26.
 I believe there is one if you need it for download from the
 developer website with Apple. Not sure how long it'll take
 for the sort of official Xcode update to show up in the App
 Store. And Microsoft today released an out-of-band
 update. Now there is a security issue being addressed
 here, but that isn't really what makes this particular
 update interesting. It fixes two complaints users had with
 last Tuesday's patch Tuesday update. Apparently for some
 users, remote desktop services was unstable. So that's one of
 the fixes. The other fix that's being addressed here is
 audio issues that came up on some Windows systems. So
 definitely that's sort of why this particular update was
 released. The security update is a refinement of a patch
 that was released I think back in March to patch a particular
 case that wasn't covered by the earlier patch. So really
 just sort of completing the patch from back then. And yes,
 that's this Windows user mode power service is the elevation
 of privilege issue that is being addressed here. And then
 we got an interesting write-up by XPatch.com releasing some
 details regarding a telegram vulnerability that was patched
 back in July. What makes this noteworthy is, well, not that
 we now have sort of an exploit for it, but that you may still
 be exposed to this vulnerability even after you
 patch telegram. The problem here is if you're exporting
 the HTML of a message that you received in telegram, well,
 due to this vulnerability, it was possible for an attacker
 to embed JavaScript in that export. Now, if you later open
 that HTML file, now it's being opened from the local file
 system. So it's running in a different trust scope of the
 browser and the JavaScript can execute and even access the
 local system. So the problem here is if in the past you
 exported chats from telegram as an HTML archive, those HTML
 archives may still contain JavaScript, even if you now
 patched a telegram. Not sure how and if that had been
 exploited, but the sounds like this kind of vulnerability is
 relatively straightforward actually to exploit. So even
 after the patch was released, if you were late patching, you
 may have had a window there where you were exposed to
 exploits. Well, and this is it for today. So thanks for
 listening. Thanks for liking. Thanks for subscribing to this
 podcast and talk to you again tomorrow. Bye.