{"id":33609,"date":"2021-09-13T16:14:25","date_gmt":"2021-09-13T20:14:25","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=33609"},"modified":"2022-11-10T12:25:17","modified_gmt":"2022-11-10T17:25:17","slug":"macos-11-6","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/09\/13\/macos-11-6\/","title":{"rendered":"macOS 11.6"},"content":{"rendered":"<p><a href=\"https:\/\/www.macrumors.com\/2021\/09\/13\/apple-releases-macos-big-sur-11-6-with-security-fixes\/\">Juli Clover<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2021\/09\/13\/apple-releases-macos-big-sur-11-6-with-security-fixes\/\"><p>According to Apple&rsquo;s release notes,  macOS Big Sur  improves the security of macOS and is recommended for all users. Apple has also released security update 2021-005 for macOS Catalina, and both updates address an issue that could allow a maliciously crafted PDF to execute code. Apple says that it is aware of a report that this bug may have been actively exploited.<\/p><\/blockquote>\n<p>It&rsquo;s unclear why this update isn&rsquo;t numbered 11.5.3. It was also weird in that the Update Now button was disabled for me in Software Update even though the text said that the update was available. I had to click the text to see the sheet with the list of updates and then click the checkbox next to it before macOS would start downloading the update.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT212804\">Apple<\/a>:<\/p>\n<blockquote cite=\"https:\/\/support.apple.com\/en-us\/HT212804\">\n<p>This document describes the security content of macOS Big Sur 11.6.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/eclecticlight.co\/2021\/09\/13\/apple-has-just-released-macos-big-sur-11-6-a-catalina-security-update-and-mrt-1-84\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2021\/09\/13\/apple-has-just-released-macos-big-sur-11-6-a-catalina-security-update-and-mrt-1-84\/\"><p>Congratulations to Mikey @0xmachos, who has worked out that the PDF vulnerability is most probably the same as the Megalodon\/FORCEDENTRY iMessage zero click exploit, involving a bug in CoreGraphics decoding JBIG2-encoded data in a PDF file.<\/p><\/blockquote>\n\n<p>See also: <a href=\"https:\/\/mrmacintosh.com\/macos-big-sur-11-6-update-20g165-is-live-whats-new\/\">Mr. Macintosh<\/a> (<a href=\"https:\/\/twitter.com\/ClassicII_MrMac\/status\/1437465686876504065\">tweet<\/a>).<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/13\/zero-click-imessage-attacks\/\">Zero-click iMessage Attacks<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/08\/11\/macos-11-5-2\/\">macOS 11.5.2<\/a><\/li>\n<\/ul>\n\n<p id=\"macos-11-6-update-2021-09-14\">Update (2021-09-14): <a href=\"https:\/\/eclecticlight.co\/2021\/09\/13\/what-has-changed-in-macos-11-6\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2021\/09\/13\/what-has-changed-in-macos-11-6\/\">\n<p>Software which has changed version or build numbers between macOS 11.5.2 and 11.6 includes[&#8230;]<\/p>\n<p>[&#8230;]<\/p>\n<p>Although it does contain some minor fixes &#x2013; that to SMB looks of potential interest &#x2013; the 11.6 update is primarily a security update.<\/p>\n<p>[&#8230;]<\/p>\n<p>If you&rsquo;re still running Mojave, this almost certainly means that your macOS is no longer supported by Apple, and may well be vulnerable to either or both of these bugs.<\/p>\n<\/blockquote>\n\n<p>The <a href=\"https:\/\/mrmacintosh.com\/macos-big-sur-full-installer-database-download-directly-from-apple\/\">standalone download<\/a> is still not available.<\/p>\n\n<p id=\"macos-11-6-update-2021-09-17\">Update (2021-09-17): <a href=\"https:\/\/twitter.com\/ClassicII_MrMac\/status\/1438942332871643138\">Mr. Macintosh<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/ClassicII_MrMac\/status\/1438942332871643138\">\n<p>The macOS Big Sur 11.6 full installer is now available. &#x1F389;<\/p>\n<\/blockquote>\n\n<p id=\"macos-11-6-update-2021-10-19\">Update (2021-10-19): <a href=\"https:\/\/eclecticlight.co\/2021\/09\/19\/last-week-on-my-mac-the-macos-update-problem\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2021\/09\/19\/last-week-on-my-mac-the-macos-update-problem\/\">\n<p>One great advantage of the new sealed system in Big Sur is that failed updates should be a thing of the past. Updating should now be almost totally reliable, and in the rare cases where something does go wrong, that Mac should be returned to its pre-update state or Recovery, ready to try again. It has been widely assumed that the primary purpose of Big Sur&rsquo;s sealed system volume is for its improved security. Although that&rsquo;s clearly important, improved reliability of updates and assurance of the total integrity of the system affect far more users directly.<\/p>\n<p>So far the big disadvantage of the new update mechanism required to accomplish this has been the size of updates. Each has brought an overhead of around 2.1 GB on Intel Macs and 3 GB on M1 models.<\/p>\n<p>[&#8230;]<\/p>\n<p>In a year&rsquo;s time, when Big Sur has reached 11.6.5, for example, how will a user be able to install or reinstall that on their Mac? Will they have to download and run the 11.6 full installer app, then use Software Update to obtain and install a single Combo update to bring that up to 11.6.5, or will they have to plod painfully through each individual delta update starting from 11.6.1 and ending with that to 11.6.5?<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Juli Clover: According to Apple&rsquo;s release notes, macOS Big Sur improves the security of macOS and is recommended for all users. Apple has also released security update 2021-005 for macOS Catalina, and both updates address an issue that could allow a maliciously crafted PDF to execute code. Apple says that it is aware of a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-09-13T20:14:28Z","apple_news_api_id":"afe96fe6-5dad-4f64-b353-115ff3780680","apple_news_api_modified_at":"2022-11-10T17:25:21Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABQ==","apple_news_api_share_url":"https:\/\/apple.news\/Ar-lv5l2tT2SzUxFf83gGgA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[131,30,1891,2303,345,48,2087],"class_list":["post-33609","post","type-post","status-publish","format-standard","hentry","category-technology","tag-bug","tag-mac","tag-macos-11-0","tag-macos-release","tag-pdf","tag-security","tag-software-update"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33609","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=33609"}],"version-history":[{"count":6,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33609\/revisions"}],"predecessor-version":[{"id":33966,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33609\/revisions\/33966"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=33609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=33609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=33609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}