[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50139-5

Platform: cpe:/o:apple:mac_os_13Date: (C)2024-04-17   (M)2024-04-17



With macOS 10.12 Sierra, Apple has introduced Siri from iOS to macOS. While there are data spillage concerns with the use of data-gathering personal assistant software, the risk here does not seem greater in sending queries to Apple through Siri than in sending search terms in a browser to Google or Microsoft. While it is possible that Siri will be used for local actions rather than Internet searches, Siri could, in theory, tell Apple about confidential Programs and Projects that should not be revealed. This appears be a usage edge case. In cases where sensitive or protected data is processed and Siri could expose that information through assisting a user in navigating their machine, it should be disabled. Siri does need to phone home to Apple, so it should not be available from air-gapped networks as part of its requirements. Most of the use case data published has shown that Siri is a tremendous time saver on iOS where multiple screens and menus need to be navigated through. Information like sports scores, weather, movie times, and simple to-do items on existing calendars can be easily found with Siri. None of the standard use cases should be more risky than already approved activity. For information on Apple's privacy policy for Siri, click here. Rationale:Where "normal" user activity is already limited, Siri use should be controlled as well. Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.applicationaccess 2. The key to include is allowAssistant 3. Set the key to <true/> or <false/> based on your organization's requirements


Parameter:

[Yes/No]


Technical Mechanism:

Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.applicationaccess 2. The key to include is allowAssistant 3. Set the key to true/ or false/ based on your organization's requirements

CCSS Severity:CCSS Metrics:
CCSS Score : 4.4Attack Vector: LOCAL
Exploit Score: 1.8Attack Complexity: LOW
Impact Score: 2.5Privileges Required: LOW
Severity: MEDIUMUser Interaction: NONE
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LScope: UNCHANGED
 Confidentiality: LOW
 Integrity: NONE
 Availability: LOW
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:99061


OVAL    1
oval:org.secpod.oval:def:99061
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_13

© SecPod Technologies