ZayNews
GBP/USD
EUR/USD
USD/JPY
GBP/EUR
Gold $/oz
Silver $/oz

Tech

Great Success from Turkish Researcher: Critical Vulnerability in Ubisoft's macOS Client!

  • In the cyber security world, desktop operating systems, and especially the macOS ecosystem, host different security layers with the transition to modern ARM64 architecture.
  • The technical studies conducted by Ali Yabuz focus exactly on this modern architecture.

Türkiye-based independent cyber security researcher Ali Yabuz revealed a critical security vulnerability in the macOS client of a popular production by Ubisoft, one of the giant names in the gaming world. This vulnerability, which was detected after an intensive reverse engineering and binary analysis process that lasted about a month, was reported directly to Ubisoft within the framework of ethical cyber security standards (Responsible Disclosure). The French gaming giant […] Turkey-based independent cyber security researcher Ali Yabuz has revealed a critical security vulnerability in the macOS client of a popular production by Ubisoft, one of the giant names in the gaming world.

The French gaming giant launched the official patch program to secure the system by verifying the extensive evidence e cyber security world, desktop operating systems, and especially the macOS ecosystem, host different security layers with the transition to modern ARM64 architecture. The technical studies conducted by Ali Yabuz focus exactly on this modern architecture. During the day and night work that lasted for about a month; In-memory runtime analyses, assembly code reviews and ARM64 binary tests are performed.

As a result of detailed analysis, all technical dimensions of the vulnerability are revealed. The researcher prepares Proof of Concept (PoC) documents showing how the vulnerability can be exploited, step-by-step reproduction steps, relevant source codes, and a demonstration video that proves the concept. All this huge technical file obtained is delivered to Ubisoft's global security and engineering units through secure communication channels.

Going into technical details, it can be seen that the detected vulnerability is in the CWE-114 (Process Control / Dynamic Link Library Infiltration) category in the cyber security literature. This type of vulnerability, which occurs due to incorrect control of dynamically managed code resources or libraries, paves the way for malicious people to inject unauthorized dynamic code blocks or external libraries into the system. Especially in software that constantly exchanges data with servers and directly access system resources, such as game clients, such vulnerabilities can put users' system security at risk.

As soon as Ubisoft's engineering teams receive the report, they understand the seriousness of the situation and take action quickly. Security Process Operation: [Binary Analysis] ➔ [PoC Documentation] ➔ [Responsible Notification] ➔ [Ubisoft Verification & Patch] Ubisoft security team, which examined the report presented by the Turkish researcher in detail, officially confirms the vulnerability and states that they have started preparations for the patch. In the company's official response to Ali Yabuz, it is emphasized how critical the contribution provided is in terms of software and infrastructure security: "We thank you for the time you took to prepare your report and share it with us.

We have forwarded your report and all the information you provided to our engineering and server teams for detailed review and planning of the necessary actions. They will meticulously correct the reported security situation and manage the patching process. In accordance with the principles of "Responsible Disclosure", which is the golden rule of the cyber security community, sensitive details are kept secret until the vulnerability is completely closed.

The name of the game, technical exploitation method and details of the vulnerability are not shared with the public until the manufacturer distributes the update globally for all players and makes the system 100% secure. After the patching process is completed, Ali Yabuz is expected to share his comprehensive analysis, including all technical details of the research, with the cyber security community. Such successes achieved by Turkish researchers internationally once again reveal the competence of the domestic cyber security ecosystem. Your comment has been sent, it will be published after approval."

Source: ShiftDelete

Most read in this category